CVE-2026-27462

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fixed in version 3.2.3.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-21 20:16

Updated : 2026-09-09 21:20


NVD link : CVE-2026-27462

Mitre link : CVE-2026-27462

CVE.ORG link : CVE-2026-27462


JSON object : View

Products Affected

No product.

CWE
CWE-204

Observable Response Discrepancy