8.8
CVE-2026-31936
- EPSS 0.27%
- Veröffentlicht 21.08.2026 22:16:36
- Zuletzt bearbeitet 09.09.2026 21:06:39
- Erkennungen
Combodo iTop: Unauthorized access to object information via search operation
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operation. This issue has been fixed in version 3.2.3.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerCombodo
≫
Produkt
iTop
Version
< 3.2.3
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.19 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/Combodo/iTop/commit/b3223eb9b6bc1514276f8f321db1e27db6f42808
https://github.com/Combodo/iTop/security/advisories/GHSA-3r3r-j29m-3v43