CVE-2025-47286 HIGH

CVE-2025-47286: Combodo iTop vulnerable to Remote Code Execution in the backup creation functionality

Vendor Combodo
Product iTop
Weakness CWE-74
Published November 10, 2025
Last update November 10, 2025

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a command based on it.

Key dates

02Disclosure timeline

November 10, 2025 CVE published
November 10, 2025 Record updated