---
id: CVE-2026-34836
title: Combodo iTop is a web based IT service management tool
summary: >-
  Combodo iTop is a web based IT service management tool. Prior to 3.2.3,
  improper access control in ajax.render.php and ajax.document.php allows for
  document access without checking on user permissions. This issue has been
  fixed in versio…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-862
published: '2026-08-21'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:06:39.057'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34836'
references:
  - url: >-
      https://github.com/Combodo/iTop/commit/77915853875710f152a873842fa2a84ebd09719b
    label: security-advisories@github.com
  - url: 'https://github.com/Combodo/iTop/security/advisories/GHSA-2gvp-4cv3-cx6j'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.0028
epssPercentile: 0.20754
ingestedAt: '2026-09-09T21:22:45.547Z'
---

## Overview

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for document access without checking on user permissions. This issue has been fixed in version 3.2.3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
