SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-30865

HIGH · CVSS 7.1 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A reflected Cross-Site Scripting (XSS) vulnerability exists in the dashboard save functionality of Combodo iTop prior to version 3.2.3, allowing attackers to execute arbitrary scripts in the context of a user's session. This can lead to unauthorized actions or data exposure, posing a significant risk to users of the IT service management tool. Organizations using affected versions should prioritize upgrading to version 3.2.3 or later to mitigate this security risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-30865
Severity
HIGH
CVSS
7.1
EPSS
0.19%

Original NVD Description

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the dashboard save functionality. This issue has been fixed in version 3.2.3.