HIGH
Combodo iTop: Weak secret generation for inline image
Published Aug 21, 2026
7.5
HIGHCVSS 3.1
EPSS 0.43%
Description
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
Affected products
-
Affected
- < 3.2.3
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (3)
- http://github.com/Combodo/iTop/commit/9c39efd9af53a1deeb578133eff7333a7b8816b0 x_refsource_MISC
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-64125 Advisory
- https://github.com/Combodo/iTop/security/advisories/GHSA-3jr5-rqmx-97gc x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| http://github.com/Combodo/iTop/commit/9c39efd9af53a1deeb578133eff7333a7b8816b0 | x_refsource_MISC | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-64125 | Advisory | |
| https://github.com/Combodo/iTop/security/advisories/GHSA-3jr5-rqmx-97gc | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 21, 2026
Updated Aug 25, 2026
Reserved Feb 19, 2026
Link CVE-2026-27490
CISA Vulnrichment
Updated Aug 25, 2026
Red Hat
No data
GitHub
No data