Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-39975: Combodo iTop allows attackers to run code remotely

CVE-2026-39975 · published 1 month ago
Summary

Versions of Combodo iTop before 3.2.3 let anyone on the internet delete a protection file and then execute their own code on the server. This could let an attacker take control of the system and access sensitive data. Upgrade to version 3.2.3 or later to close the gap.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
combodo itop < 3.2.3
Original advisory text
Combodo iTop: Remote code execution using external auth variable value
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process, prevents users from performing write actions. This issue has been fixed in version 3.2.3.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-94Code Injection
Timeline
Published24 Aug 2026
Updated3 Oct 2026
First seen24 Aug 2026
Sources
CVE-2026-39975 · MITRE
Track software like this
Free during beta