Combodo iTop, a web-based IT service management tool, contains a user enumeration vulnerability in its password reset mechanism prior to version 3.2.3. The application returns different responses for valid versus invalid usernames during the password reset process, allowing attackers to enumerate valid user accounts. This information disclosure weakness could facilitate targeted attacks by identifying existing users. The vulnerability affects all iTop versions prior to 3.2.3. A fix has been released in version 3.2.3. The issue is tracked as CVE-2026-27462 and was disclosed via GitHub Security Advisories.