---
id: CVE-2026-27463
title: Combodo iTop is a web based IT service management tool
summary: >-
  Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the
  HTML title attribute of the logo in the login page contains the complete iTop
  version. This issue has been fixed in version 3.2.3.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
published: '2026-08-21'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:20:38.860'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-27463'
references:
  - url: >-
      https://github.com/Combodo/iTop/commit/d124f8ee58fa243193184ac2c55a561acdded356
    label: security-advisories@github.com
  - url: 'https://github.com/Combodo/iTop/security/advisories/GHSA-hm9q-8jx3-f3v5'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.0025
epssPercentile: 0.16632
ingestedAt: '2026-09-09T21:22:45.546Z'
---

## Overview

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains the complete iTop version. This issue has been fixed in version 3.2.3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
