---
id: CVE-2025-47286
title: Combodo iTop is a web based IT service management tool
summary: >-
  Combodo iTop is a web based IT service management tool. In versions prior to
  2.7.13 and 3.2.2, an administrator can, by editing the configuration of the
  iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape
  and chec…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-74
vendor: combodo
product: itop
affected:
  - itop < 2.7.13
  - 'itop >= 3.0.0, < 3.2.2'
patched:
  - itop 3.2.2
published: '2025-11-10'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-47286'
references:
  - url: 'https://github.com/Combodo/iTop/security/advisories/GHSA-4w93-rw6g-5m9c'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00467
epssPercentile: 0.38418
ingestedAt: '2026-10-07T21:54:15.003Z'
---

## Overview

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a command based on it.

## Affected

- `itop < 2.7.13`
- `itop >= 3.0.0, < 3.2.2`

## Remediation

Upgrade past the affected range:

- `itop 3.2.2`
