---
id: CVE-2026-34948
title: Combodo iTop is a web based IT service management tool
summary: >-
  Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only
  classes present in the SELECT clause are protected by the silos access check
  in OQL. This issue has been fixed in version 3.2.3.
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-200
published: '2026-08-21'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:06:39.057'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34948'
references:
  - url: >-
      https://github.com/Combodo/iTop/commit/e467ca83cfcfc5ba1f1d78a99d4805e595f114ba
    label: security-advisories@github.com
  - url: 'https://github.com/Combodo/iTop/security/advisories/GHSA-cm4j-52rf-whgc'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00386
epssPercentile: 0.29811
ingestedAt: '2026-09-09T21:22:45.548Z'
---

## Overview

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are protected by the silos access check in OQL. This issue has been fixed in version 3.2.3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
