SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-30864

HIGH · CVSS 8.9 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The dashboard revert functionality in Combodo iTop versions prior to 3.2.3 is susceptible to reflected cross-site scripting (XSS), allowing attackers to inject malicious scripts that could compromise user sessions or manipulate web content. Organizations using affected versions of iTop should prioritize upgrading to version 3.2.3 or later to mitigate the risk of exploitation. This vulnerability is particularly critical for IT service management environments where sensitive data and user interactions are prevalent.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-30864
Severity
HIGH
CVSS
8.9
EPSS
0.20%

Original NVD Description

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.