Hardcoded credentials in Comarch ERP Optima
Vulnerability Description
Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elevated privileges including executing system commands on a server. This issue has been fixed in version 2026.4
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-68421
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Wojciech Giełda
Affected Vendor
Comarch
View all reports →