CVE-2026-27462
Received Received - Intake

Authentication Bypass in Combodo iTop via User Enumeration

Vulnerability report for CVE-2026-27462, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: GitHub, Inc.

Description

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fixed in version 3.2.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-22
AI Q&A
2026-08-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
combodo itop 3.2.3
combodo itop 3.3.0
combodo itop to 3.2.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-204 The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-27462 is a user enumeration vulnerability in Combodo iTop versions before 3.2.3. The password reset mechanism returns different responses for valid and invalid usernames, allowing attackers to determine if a username exists in the system.

Detection Guidance

To detect this vulnerability, monitor password reset responses for discrepancies between valid and invalid usernames. Check if the application returns different HTTP status codes, error messages, or response times for valid vs invalid usernames during password reset requests.

Impact Analysis

An attacker could exploit this to identify valid usernames, which may lead to targeted phishing attacks or brute-force attempts. The vulnerability does not require privileges or user interaction and can be exploited remotely.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by exposing user information through user enumeration. GDPR requires protecting personal data and preventing unauthorized access, while HIPAA mandates safeguarding protected health information. The ability to determine valid usernames may violate these regulations by enabling unauthorized data disclosure.

Mitigation Strategies

Upgrade iTop to version 3.2.3 or later immediately. If upgrading is not possible, apply the patch from the GitHub commit referenced in Resource 2 to standardize password reset error messages and prevent user enumeration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-27462. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart