8.7
/ 10
HIGH
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Description
Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elevated privileges including executing system commands on a server.
This issue has been fixed in version 2026.4
This issue has been fixed in version 2026.4
AI Analysis
Hardcoded database credentials allow remote attackers to gain elevated access and execute system commands
Basic Information
ID
CVE-2025-68421
Source
CERT-PL
Published
May 14, 2026 at 10:35
Affected Product
Vendor
Comarch
Product
ERP Optima
Affected Versions
Comarch ERP Optima 0
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
Comarch
Product
Comarch ERP Optima