← Back
CVE-2026-40877
high
CVSS 8.7
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Summary
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
AI summary openai / gpt-4o
Combodo iTopは、バージョン3.2.3より前の版でPHPオブジェクトインジェクション脆弱性を含んでおり、これによりリモートコード実行の可能性がある。この問題は最新のバージョンで修正されている。
❓ What is the problem
Combodo iTopのユーザープリファレンス機能におけるPHPオブジェクトインジェクション脆弱性。
📍 Affected scope
iTopのバージョン3.2.3より前のユーザープリファレンス機能。
🔥 Severity
高いリスク。リモートコード実行が可能であるため。
🔧 How to fix
バージョン3.2.3にアップデートしてください。
🛡️ Workaround
情報なし
🔍 Detection
iTopのバージョンを確認して3.2.3未満である場合は脆弱性の影響を受けている可能性があります。