CVE-2026-27490CWE-330CWE-331
CVE-2026-27490
High · published August 22, 2026
What it is
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
The record
Technical detail
- CVSS v3.1
- 7.5 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00314 · 23.9th percentile
- Weaknesses
- CWE-330 · Use of Insufficiently Random Values; CWE-331 · Insufficient Entropy
- Published
- 2026-08-22T00:16Z
References (2)
EPSS history
Timeline