CVE-2026-33333
Received Received - Intake

Sensitive Information Disclosure in Combodo iTop

Vulnerability report for CVE-2026-33333, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: GitHub, Inc.

Description

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has been fixed in version 3.2.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-22
AI Q&A
2026-08-22
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
combodo itop to 3.2.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-209 The product generates an error message that includes sensitive information about its environment, users, or associated data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Combodo iTop versions prior to 3.2.3 involves sensitive information being disclosed in error messages. Attackers could potentially access this information if they trigger error conditions in the application.

Detection Guidance

This vulnerability involves sensitive information disclosure in error messages. To detect it, monitor application logs for error messages that may expose sensitive data. Check if your iTop version is below 3.2.3 by running commands like 'grep -r "iTop" /path/to/installation' or checking the version in the web interface or configuration files.

Impact Analysis

The impact includes exposure of sensitive data through error messages, which could lead to unauthorized information access. However, exploitation requires user interaction and the attacker must have low privileges.

Compliance Impact

This vulnerability could potentially violate compliance requirements by exposing sensitive data, which may conflict with GDPR or HIPAA obligations to protect personal or health information.

Mitigation Strategies

Upgrade iTop to version 3.2.3 or later immediately to patch the vulnerability. If upgrading is not possible, review and restrict error message details in configuration to avoid exposing sensitive information. Ensure proper access controls are in place to limit UI access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33333. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart