Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elevated privileges including executing system commands on a server.
This issue has been fixed in version 2026.4
This issue has been fixed in version 2026.4
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Since these accounts are used for backward compatibility only, in some cases it is possible to disable them in the SQL server.
References
History
Thu, 14 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elevated privileges including executing system commands on a server. This issue has been fixed in version 2026.4 | |
| Title | Hardcoded credentials in Comarch ERP Optima | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-05-14T10:35:04.752Z
Reserved: 2025-12-17T14:10:16.437Z
Link: CVE-2025-68421
No data.
Status : Received
Published: 2026-05-14T11:16:17.240
Modified: 2026-05-14T11:16:17.240
Link: CVE-2025-68421
No data.
OpenCVE Enrichment
Updated: 2026-05-14T11:30:16Z
Weaknesses