Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process, prevents users from performing write actions. This issue has been fixed in version 3.2.3. | |
| Title | Combodo iTop: Remote code execution using external auth variable value | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-24T19:58:25.146Z
Reserved: 2026-04-08T00:01:47.628Z
Link: CVE-2026-39975
No data.
Status : Received
Published: 2026-08-24T19:16:38.470
Modified: 2026-08-24T19:16:38.470
Link: CVE-2026-39975
No data.
OpenCVE Enrichment
No data.