CVE-2026-27463
Received Received - Intake

Information Disclosure in iTop Login Page

Vulnerability report for CVE-2026-27463, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: GitHub, Inc.

Description

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains the complete iTop version. This issue has been fixed in version 3.2.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-22
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
combodo itop to 3.2.3 (exc)
combodo itop 3.2.3
combodo itop 3.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-27463 is a vulnerability in Combodo iTop versions prior to 3.2.3 where the HTML title attribute of the login page logo exposes the complete iTop version. This allows attackers to identify vulnerable systems by viewing the version information in the page source or browser title.

Detection Guidance

Check the HTML source of the iTop login page for the logo title attribute containing the version number. Use curl or browser dev tools to inspect the page source for versions prior to 3.2.3.

Impact Analysis

This vulnerability could help attackers identify systems running outdated iTop versions, potentially enabling targeted exploits. It does not directly compromise data but may facilitate further attacks by revealing version-specific weaknesses.

Compliance Impact

This vulnerability exposes sensitive version information through the HTML title attribute of the login page logo in iTop versions prior to 3.2.3. While not directly violating GDPR or HIPAA, such information exposure could indirectly support attackers in targeting systems, potentially leading to further exploits that may impact data confidentiality or integrity. Organizations using affected versions should patch to mitigate risks.

Mitigation Strategies

Upgrade iTop to version 3.2.3 or later. Remove or modify the logo title attribute in the login page HTML if customization is not possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-27463. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart