CVE-2026-108717
Received Received - Intake

Authorization Bypass in iTop Console via LinkSetController

Vulnerability report for CVE-2026-108717, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Combodo iTop 3.1.0 through 3.3.0 contains a missing authorization vulnerability in LinkSetController.php that allows authenticated console users to bypass profile grants by supplying arbitrary class and key parameters. Attackers can invoke the linkset delete, detach and get-remote-object routes to delete objects, clear external keys, and read object attributes without permission.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Combodo iTop 3.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108717 is a missing authorization vulnerability in Combodo iTop versions 3.1.0 through 3.3.0. It exists in LinkSetController.php where authenticated users can bypass profile restrictions by supplying arbitrary class and key parameters. This allows invoking routes to delete objects, clear external keys, or read object attributes without proper permissions.

Detection Guidance

Check for unauthorized access to LinkSetController.php routes by monitoring HTTP requests to /linkset/delete, /linkset/detach, and /linkset/get-remote-object. Review logs for suspicious activity involving arbitrary class and key parameters. Verify if users with minimal permissions can perform delete, detach, or read operations on objects outside their granted access.

Impact Analysis

An attacker with authenticated access could delete or modify objects, clear external keys, or read sensitive attributes outside their granted permissions. This includes accessing objects in other organization silos or instance-wide for non-silo classes, potentially leading to data loss, unauthorized changes, or information disclosure.

Compliance Impact

This vulnerability could lead to unauthorized data deletion, modification, or disclosure, violating GDPR's data integrity and confidentiality principles or HIPAA's access control requirements. Non-compliance risks include legal penalties, reputational damage, and loss of trust due to compromised data security.

Mitigation Strategies

Upgrade iTop to the latest version beyond 3.3.0 where this issue is patched. Apply strict input validation for class and key parameters in LinkSetController.php. Enforce authorization checks for all linkset routes to ensure users cannot bypass profile grants. Disable unused linkset routes if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108717. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart