Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-39975: Combodo iTop allows attackers to run code remotely
CVE-2026-39975 · published 1 month ago
Summary
Versions of Combodo iTop before 3.2.3 let anyone on the internet delete a protection file and then execute their own code on the server. This could let an attacker take control of the system and access sensitive data. Upgrade to version 3.2.3 or later to close the gap.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| combodo | itop | < 3.2.3 |
Original advisory text
Combodo iTop: Remote code execution using external auth variable value
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process, prevents users from performing write actions. This issue has been fixed in version 3.2.3.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-94Code Injection
Timeline
Published24 Aug 2026
Updated3 Oct 2026
First seen24 Aug 2026
Track software like this
Free during beta