These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-40877 is a PHP object injection vulnerability in Combodo iTop's user preference functionality, potentially leading to remote code execution. This issue was fixed in version 3.2.3. The vulnerability exists in the user preference functionality of Combodo iTop, which could allow an attacker to inject malicious PHP objects, potentially leading to remote code execution. The fix was implemented in vers [truncated]
CVE-2026-39975 is a critical vulnerability in Combodo iTop, a web-based IT service management tool. Prior to version 3.2.3, unauthenticated users could delete the .readonly file, leading to code execution. This file prevents write actions and is created during setup. The issue is fixed in version 3.2.3. Defenders should verify exposure and apply remediation for iTop instances, especially those with unauth [truncated]
CVE-2026-30864 is a Reflected Cross-Site Scripting (XSS) vulnerability in Combodo iTop's dashboard revert functionality. This issue was fixed in version 3.2.3. The vulnerability allows attackers to inject malicious scripts, potentially leading to unauthorized actions or data theft. Defenders should prioritize verifying exposure and applying the patch to prevent potential XSS attacks. The CVE record and NV [truncated]
Combodo iTop, a web-based IT service management tool, has a Reflected Cross-Site Scripting (XSS) vulnerability in its universal search functionality prior to version 3.2.3. This vulnerability, classified as HIGH with a CVSS score of 8, allows attackers to inject malicious JavaScript code, potentially leading to unauthorized actions or data exposure. Organizations using Combodo iTop versions prior to 3.2.3 [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T21:16:57.250Z and has not been modified since then. Combodo iTop, a web-based IT service management tool, has a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php prior to version 3.2.3. This type of vulnerability allows an attacker to inject malicious scripts into the appli [truncated]
CVE-2026-30826 is a Reflected Cross-Site Scripting (XSS) vulnerability in Combodo iTop prior to version 3.2.3. The vulnerability is related to the testing OQL query functionality. This type of vulnerability allows an attacker to inject malicious scripts into the application, potentially leading to unauthorized actions or data breaches. Affected deployments likely involve web-based IT service management sy [truncated]
Combodo iTop, a web-based IT service management tool, is affected by a user enumeration vulnerability. This issue, identified as CVE-2026-27462, exists in versions prior to 3.2.3. The vulnerability arises from the reset password mechanism, which returns different responses for valid and invalid usernames, allowing attackers to enumerate users. The CVE record was published on 2026-08-21T20:16:33.870Z and h [truncated]