{"api_version":"1","generated_at":"2026-09-04T10:44:41+00:00","cve":"CVE-2026-40877","urls":{"html":"https://cve.report/CVE-2026-40877","api":"https://cve.report/api/cve/CVE-2026-40877.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-40877","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-40877"},"summary":{"title":"Combodo iTop: PHP Object Injection Leading to Remote Code Execution on user preferences","description":"Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-08-24 19:16:38","updated_at":"2026-08-24 19:16:38"},"problem_types":["CWE-94","CWE-502","CWE-502 CWE-502: Deserialization of Untrusted Data","CWE-94 CWE-94: Improper Control of Generation of Code ('Code Injection')"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"8.7","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.7","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/Combodo/iTop/security/advisories/GHSA-3mq5-p5vh-cw7r","name":"https://github.com/Combodo/iTop/security/advisories/GHSA-3mq5-p5vh-cw7r","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-40877","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40877","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Combodo","product":"iTop","version":"affected < 3.2.3","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"40877","cve":"CVE-2026-40877","epss":"0.003180000","percentile":"0.239940000","score_date":"2026-08-25","updated_at":"2026-08-26 00:12:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"product":"iTop","vendor":"Combodo","versions":[{"status":"affected","version":"< 3.2.3"}]}],"descriptions":[{"lang":"en","value":"Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-502","description":"CWE-502: Deserialization of Untrusted Data","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-94","description":"CWE-94: Improper Control of Generation of Code ('Code Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-24T18:57:55.017Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/Combodo/iTop/security/advisories/GHSA-3mq5-p5vh-cw7r","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Combodo/iTop/security/advisories/GHSA-3mq5-p5vh-cw7r"}],"source":{"advisory":"GHSA-3mq5-p5vh-cw7r","discovery":"UNKNOWN"},"title":"Combodo iTop: PHP Object Injection Leading to Remote Code Execution on user preferences"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-40877","datePublished":"2026-08-24T18:57:55.017Z","dateReserved":"2026-04-15T15:57:41.719Z","dateUpdated":"2026-08-24T18:57:55.017Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-24 19:16:38","lastModifiedDate":"2026-08-24 19:16:38","problem_types":["CWE-94","CWE-502","CWE-502 CWE-502: Deserialization of Untrusted Data","CWE-94 CWE-94: Improper Control of Generation of Code ('Code Injection')"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"40877","Ordinal":"1","Title":"Combodo iTop: PHP Object Injection Leading to Remote Code Execut","CVE":"CVE-2026-40877","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"40877","Ordinal":"1","NoteData":"Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.","Type":"Description","Title":"Combodo iTop: PHP Object Injection Leading to Remote Code Execut"}]}}}