Sceawere
Vulnerability Detail
CVE-2026-108717UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
iTop Authorization Bypass in LinkSetController
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 4h ago
- Vendor
- Combodo
- Product
- iTop
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Combodo iTop 3.1.0 through 3.3.0 contains a missing authorization vulnerability in LinkSetController.php that allows authenticated console users to bypass profile grants by supplying arbitrary class and key parameters. Attackers can invoke the linkset delete, detach and get-remote-object routes to delete objects, clear external keys, and read object attributes without permission.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-11T13:17:14.870Z",
"pubdate": "2026-10-11T13:17:14.870Z",
"executiveSummary": "Combodo iTop versions 3.1.0 through 3.3.0 are affected by a critical missing authorization vulnerability located within the LinkSetController.php component.\nThe vulnerability allows authenticated console users to circumvent existing profile-based access controls and security grants.\nBy manipulating arbitrary class and key parameters, an attacker can invoke sensitive internal routes, specifically those responsible for deleting objects, detaching associations, and retrieving remote object attributes.\nThis flaw effectively elevates the privileges of any authenticated console user, enabling them to perform unauthorized data modification, integrity destruction, and sensitive information disclosure.\nThe risk is significant as it permits lateral movement or malicious configuration changes within the IT Service Management (ITSM) platform regardless of the user's assigned role or permissions.\nExploitation requires active authentication to the iTop console, but does not necessitate elevated administrative privileges, making it accessible to any legitimate, low-privileged user account.",
"technicalDetails": "The root cause of this vulnerability lies in the improper implementation of authorization checks within the LinkSetController.php controller in Combodo iTop. The application fails to validate whether the current user possesses the necessary permissions to perform operations on specific objects passed via user-supplied parameters.\nSpecifically, the LinkSetController exposes routes designated for 'linkset delete', 'detach', and 'get-remote-object' operations. These internal functions are intended for legitimate system operations; however, they lack a robust server-side security gatekeeper to verify authorization grants before executing the requested logic.\nAn attacker can exploit this by crafting HTTP requests that target these specific routes while injecting arbitrary 'class' and 'key' parameters into the payload. When the LinkSetController processes these parameters, it performs the requested actions—such as database record deletion, object detachment, or attribute read operations—on behalf of the attacker, ignoring any restrictions defined by the user’s assigned profile.\nThe attack flow proceeds as follows: First, the authenticated attacker identifies a valid class and object key identifier that they wish to manipulate. Second, the attacker triggers the vulnerable route (e.g., delete or get-remote-object) by submitting a forged request. Third, the LinkSetController fails to verify if the attacker has the 'delete' or 'read' grant for the specific class requested. Consequently, the application executes the requested operation directly, resulting in unauthorized data modification or unauthorized information leakage.\nThis vulnerability is particularly severe because the LinkSetController acts as a bridge for complex object relationships within the iTop framework. By manipulating the 'linkset' parameters, an attacker can clear external keys, thereby disrupting business logic or destroying dependencies between service management entities.\nSince the vulnerability exists at the controller layer and manages object-level operations, the impact is comprehensive. It allows for the subversion of the entire security model regarding object access, essentially granting the attacker the ability to manipulate any data that the controller is capable of touching, irrespective of the intended security policy."
}