Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 11 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Combodo iTop 3.1.0 through 3.3.0 contains a missing authorization vulnerability in LinkSetController.php that allows authenticated console users to bypass profile grants by supplying arbitrary class and key parameters. Attackers can invoke the linkset delete, detach and get-remote-object routes to delete objects, clear external keys, and read object attributes without permission. | |
| Title | Combodo iTop 3.1.0 through 3.3.0 Missing Authorization via LinkSetController | |
| First Time appeared |
Combodo
Combodo itop |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Combodo
Combodo itop |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T12:19:29.379Z
Reserved: 2026-10-11T01:51:50.144Z
Link: CVE-2026-108717
No data.
No data.
No data.
OpenCVE Enrichment
No data.