CVE-2025-68420
Privilege Escalation in Comarch ERP Optima
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in. It is possible for a local attacker who controls the client process to dump it's memory, extract credentials and use them to gain a privileged access to the database. In order to exploit this vulnerability, the client application has to be already configured, but a user does not have to be logged in. This issue has been fixed in version 2026.4
| CWE | CWE-266 |
| Vendor | comarch |
| Product | erp optima |
| Published | May 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for comarch erp optima
Be the first to know when new unknown vulnerabilities affecting comarch erp optima are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Comarch / ERP Optima
0 < 2026.4
References
Credits
Wojciech Giełda