Description
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has been fixed in version 3.2.3.
Published: 2026-08-21
Score: 3.5 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Prior to version 3.2.3, Combodo iTop’s ajax.render.php returned error messages that included sensitive internal information. The disclosed data can expose configuration details and other confidential information to unauthorized users, creating a risk of data leakage. The vulnerability is classified as CWE-209: Information Exposure Through an Error Message and carries a CVSS score of 3.5, indicating a low severity impact on confidentiality.

Affected Systems

The flaw affects the Combodo iTop IT service management tool for all releases prior to 3.2.3. Any deployment running iTop 3.2.2 or older is vulnerable, regardless of platform or operating system.

Risk and Exploitability

The CVSS score of 3.5 results in a low overall severity, and the EPSS score is not available, suggesting limited evidence of exploitation. Because the flaw is revealed through error handling on the web interface, the likely attack vector is unauthenticated or low-privilege access that triggers an error condition. The vulnerability is not listed in the CISA KEV catalog, reinforcing the low risk assessment for large‑scale exploitation.

Generated by OpenCVE AI on August 21, 2026 at 23:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to iTop 3.2.3 or a later version which contains the fix for the error message disclosure.
  • If an upgrade is not immediately possible, apply the commit referenced in the advisory (170014e8f0a01fb8f8581902c665ff5c1fcc1168) to patch the affected code path.
  • Reconfigure iTop to suppress detailed error messages in production, ensuring that only generic error information is presented to users.

Generated by OpenCVE AI on August 21, 2026 at 23:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Combodo
Combodo itop
Vendors & Products Combodo
Combodo itop

Fri, 21 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has been fixed in version 3.2.3.
Title Combodo iTop: Information disclosure in ajax.render.php
Weaknesses CWE-209
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-21T21:46:00.590Z

Reserved: 2026-03-18T22:15:11.812Z

Link: CVE-2026-33333

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T22:16:37.003

Modified: 2026-08-21T22:16:37.003

Link: CVE-2026-33333

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T23:30:17Z

Weaknesses
  • CWE-209

    Generation of Error Message Containing Sensitive Information