CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-34836

mediumCVSS 6.5covered by 1 sourcefirst seen 2026-08-21
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for document access without checking on user permissions. This issue has been fixed in version 3.2.3.

⚡ Watch CVE-2026-34836

Get an email if CVE-2026-34836 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-34836

CVE.org record

Embed the live status

CVE-2026-34836 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-34836 status](https://www.csirts.com/badge/CVE-2026-34836)](https://www.csirts.com/cve/CVE-2026-34836)