CVE-2025-68421
Hardcoded credentials in Comarch ERP Optima
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elevated privileges including executing system commands on a server. This issue has been fixed in version 2026.4
| CWE | CWE-798 |
| Vendor | comarch |
| Product | erp optima |
| Published | May 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for comarch erp optima
Be the first to know when new unknown vulnerabilities affecting comarch erp optima are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Comarch / ERP Optima
0 < 2026.4
References
Credits
Wojciech Gieลda