cbcvebase.
CVE-2026-40877
published 2026-08-24

CVE-2026-40877: Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which…

PriorityP353high8.7CVSS 3.1
AVNACLPRLUIRSCCHIHAN
EPSS
0.32%
24.9th percentile
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.

Affected

1 ranges
VendorProductVersion rangeFixed in
combodoitop< 3.2.33.2.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.