CVE-2026-27462
EUVD-2026-6412221.08.2026, 20:16
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fixed in version 3.2.3.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| combodo | itop | 𝑥 < 3.2.3 | CNA |
Common Weakness Enumeration