Sceawere

Vulnerability Detail

CVE-2026-27462UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Combodo iTop User Enumeration Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
2h ago
Vendor
Combodo
Product
iTop
Attack Type
CWE-204: Observable Response Discrepancy
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fixed in version 3.2.3.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-21T20:16:33.870Z",
  "pubdate": "2026-08-21T20:16:33.870Z",
  "executiveSummary": "Combodo iTop prior to version 3.2.3 suffers from a user enumeration vulnerability within its password reset mechanism.\nThe vulnerability is characterized by differential responses returned by the application when processing valid versus invalid usernames, influenced by multiple underlying application factors.\nThe primary impact of this flaw is unauthorized information disclosure, allowing remote attackers to harvest valid system usernames.\nThis harvested intelligence can subsequently facilitate brute-force attacks, credential stuffing, or targeted social engineering campaigns against system users.\nExploitation requires no prior authentication and can be executed remotely over the network by interacting with the password reset functionality.\nThe issue has been officially addressed and resolved in Combodo iTop version 3.2.3 through proper handling of reset responses.\nRisk implications include compromised user privacy and a reduced security posture regarding authentication boundaries.",
  "technicalDetails": "The vulnerability resides in the password reset mechanism of Combodo iTop prior to version 3.2.3, specifically within the logic handling identity verification and user lookup routines.\nThe root cause stems from inconsistent server-side application responses, error messages, or processing time variations when the password reset function is queried with existing versus non-existent usernames.\nNetwork exposure is remote, as the reset password mechanism is accessible over standard web protocols (HTTP/HTTPS) without requiring pre-authentication or specific privilege levels.\nThe attack flow proceeds as follows: First, an unauthenticated attacker initiates a password reset request via the application interface, supplying a target username string. Second, the backend component queries the database or internal user directory to validate the existence of the supplied username. Third, due to flawed conditional logic or differential handling based on multiple internal factors, the application returns a distinct HTTP response, status code, or structural payload variation depending on whether the account exists. Fourth, the attacker analyzes these response differentials to conclusively determine the validity of the tested username.\nPost-exploitation impact involves the systematic compilation of valid user accounts, which lowers the barrier for secondary authentication-based attacks such as credential stuffing or targeted password guessing against the Combodo iTop installation.\nThe vulnerable component is the password reset handler responsible for user lookup and feedback generation.\nAll Combodo iTop versions prior to 3.2.3 are affected by this logic flaw."
}
CVE-2026-27462: Combodo iTop User Enumeration Vulnerability (HIGH Severity, CVSS: 7.5) - Sceawere