CVE-2026-34836

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for document access without checking on user permissions. This issue has been fixed in version 3.2.3.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-21 22:16

Updated : 2026-09-09 21:06


NVD link : CVE-2026-34836

Mitre link : CVE-2026-34836

CVE.ORG link : CVE-2026-34836


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization