← Retour
CVE-2026-40877
high
CVSS 8.7
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Résumé
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2026-40877** a été découverte dans CVE-2026-40877.
Des informations confidentielles peuvent être exposées. Score CVSS : 8.7/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « CVE-2026-40877 CVE-2026-40877 » sur le site de l'éditeur.
CVE-2026-40877 (CVE-2026-40877) — CWE-94 / CVSS v3 8.7
Vecteur d'attaque : distant (réseau)
Versions affectées : `<3.2.3`
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
Combodo iTopのユーザープリファレンス機能におけるPHPオブジェクトインジェクション脆弱性。
📍 Périmètre concerné
iTopのバージョン3.2.3より前のユーザープリファレンス機能。
🔥 Gravité
高いリスク。リモートコード実行が可能であるため。
🔧 Comment corriger
バージョン3.2.3にアップデートしてください。
🛡️ Contournement
情報なし
🔍 Détection
iTopのバージョンを確認して3.2.3未満である場合は脆弱性の影響を受けている可能性があります。