CVE-2026-30866

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-21 20:16

Updated : 2026-09-09 21:20


NVD link : CVE-2026-30866

Mitre link : CVE-2026-30866

CVE.ORG link : CVE-2026-30866


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-306

Missing Authentication for Critical Function