CVE-2026-34741 affects Combodo iTop, a web-based IT service management tool. Prior to version 3.2.3, an authentication bypass vulnerability allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on new iTop instances running in production environments. The flaw poses a critical risk as it requires no authentication to exploit, enabling full remote code execution. The vulnerability has been patched in iTop version 3.2.3. A fix was committed to the official GitHub repository and a security advisory was published via GitHub Security Advisories. Organizations running iTop versions prior to 3.2.3 are urged to upgrade immediately. No workaround details are provided beyond applying the official patch.