Description
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains the complete iTop version. This issue has been fixed in version 3.2.3.
Published: 2026-08-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker to learn the exact iTop version by inspecting the HTML title attribute of the logo on the login page. This is an information disclosure flaw that can aid attackers in tailoring subsequent exploits but does not directly compromise authorization or integrity. The flaw is identified as CWE-200 and results in a moderate confidentiality impact.

Affected Systems

All Combodo iTop installations running any version older than 3.2.3 contain the flaw. The issue is resolved in version 3.2.3 and later; therefore any deployment that has not applied that update is affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk profile. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote web-based, where any unauthenticated user can view the login page and read the title attribute of the logo. Because the disclosed information is only the version number, the exploitation path is limited to reconnaissance and does not lead to immediate elevation of privileges or denial of service.

Generated by OpenCVE AI on August 21, 2026 at 21:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Combodo iTop version 3.2.3 or later to permanently eliminate the version disclosure.
  • If an upgrade cannot be applied immediately, modify the login page theme or template to remove or anonymize the title attribute of the logo so that it no longer presents the version string.
  • Maintain a monitoring process to review the login page after any customizations or updates to ensure the version information remains hidden.

Generated by OpenCVE AI on August 21, 2026 at 21:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Combodo
Combodo itop
Vendors & Products Combodo
Combodo itop

Fri, 21 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Description Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains the complete iTop version. This issue has been fixed in version 3.2.3.
Title Combodo iTop: Version disclosure via login page logo
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-21T21:43:20.794Z

Reserved: 2026-02-19T17:25:31.101Z

Link: CVE-2026-27463

cve-icon Vulnrichment

Updated: 2026-08-21T21:09:29.361Z

cve-icon NVD

Status : Deferred

Published: 2026-08-21T20:16:34.017

Modified: 2026-09-09T21:20:38.860

Link: CVE-2026-27463

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor