---
id: CVE-2026-40877
title: Combodo iTop is a web-based IT service management tool
summary: >-
  Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop
  is vulnerable to PHP object injection in the user preference functionality,
  which can lead to remote code execution. This issue has been fixed in version
  3.2.3.
severity: high
cvss: 8.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-94
  - CWE-502
published: '2026-08-24'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:06:39.057'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-40877'
references:
  - url: 'https://github.com/Combodo/iTop/security/advisories/GHSA-3mq5-p5vh-cw7r'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00533
epssPercentile: 0.42603
ingestedAt: '2026-09-09T21:22:45.549Z'
---

## Overview

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
