CVE-2026-34741: CWE-306: Missing Authentication for Critical Function in Combodo iTop
Description
Combodo iTop versions prior to 3.2.3 contain a vulnerability that allows unauthenticated remote attackers to bypass authentication and execute arbitrary PHP files from the env-production directory on new iTop instances in production environments. This issue has been fixed in version 3.2.3.
CVSS v3.1
Score 8.6high
Affected software
Combodo
iTop
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-34741 is a CWE-306 (Missing Authentication for Critical Function) vulnerability in Combodo iTop, a web-based IT service management tool. Versions before 3.2.3 allow unauthenticated remote attackers to bypass authentication controls and execute arbitrary PHP files located in the env-production directory on new iTop instances deployed in production. This flaw enables attackers to perform unauthorized code execution remotely. The vulnerability has been addressed and fixed in version 3.2.3.
Potential Impact
The vulnerability permits unauthenticated remote attackers to execute arbitrary PHP code, potentially leading to unauthorized system access and control. The CVSS v3.1 score is 8.6 (high severity), reflecting network attack vector, low attack complexity, no privileges or user interaction required, with low confidentiality impact but high integrity and low availability impacts.
Mitigation Recommendations
Upgrade affected iTop instances to version 3.2.3 or later, where this authentication bypass vulnerability has been fixed. No other mitigations are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-03-30T19:17:10.224Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a88cc60acd9273b49cc786a
Added to database: 08/21/2026, 22:08:32 UTC
Last enriched: 09/10/2026, 15:34:01 UTC
Last updated: 10/05/2026, 18:48:18 UTC
Views: 81
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.