---
id: CVE-2026-39975
title: Combodo iTop is a web-based IT service management tool
summary: >-
  Combodo iTop is a web-based IT service management tool. Prior to 3.2.3,
  unauthenticated users could delete the .readonly file on iTop instances,
  leading to code execution. This file, created during the setup process,
  prevents users from …
severity: none
cwe:
  - CWE-94
published: '2026-08-24'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:06:39.057'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-39975'
references:
  - url: 'https://github.com/Combodo/iTop/security/advisories/GHSA-h823-537c-xwfh'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00591
epssPercentile: 0.46079
ingestedAt: '2026-09-09T21:22:45.549Z'
---

## Overview

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process, prevents users from performing write actions. This issue has been fixed in version 3.2.3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
