SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-31880

HIGH · CVSS 8 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A reflected Cross-Site Scripting (XSS) vulnerability exists in the universal search feature of Combodo iTop prior to version 3.2.3, allowing attackers to inject malicious scripts that could compromise user sessions or manipulate web content. Organizations using affected versions of this IT service management tool should prioritize upgrading to version 3.2.3 or later to mitigate potential exploitation risks. This vulnerability poses a significant threat to any entity relying on iTop for IT service management, particularly those handling sensitive data.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-31880
Severity
HIGH
CVSS
8
EPSS
0.23%

Original NVD Description

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2.3.