CVE-2026-34741
⚠️ highSummary
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance in the production environment. This issue has been fixed in version 3.2.3.
CVSS Score
8.6
High
EPSS Score
0.5
Exploit Probability
Published Date
2026-08-21
First Seen: 2026-08-22
📊 Relative Risk Intelligence
This CVE is High Risk - more severe than 80.2% of all 348,756 vulnerabilities in our database.
#69,090
Top 25% most severe
Severity Percentile
Last Modified
2026-08-21
Source
NVD 🔗
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
CWE IDs (Weakness Types)