# Simple.ERP SQL injection fixed in update

Published: 2026-02-26 · Severity: medium
Canonical: https://vorant.io/reports/4129dccf-087b-5c0a-94af-d89f4a26bce3/simple-erp-sql-injection-fixed-in-update

> A SQL injection vulnerability in Simple.ERP's search function allows authenticated attackers to execute arbitrary SQL commands, patched in version 4.4.02_u06.

CERT Polska coordinated the disclosure of CVE-2026-1198, a SQL injection vulnerability affecting Simple.ERP enterprise resource planning software. The flaw exists in the search functionality within the "Obroty na kontach" (Account Turnover) window, where insufficient input validation permits authenticated users to execute arbitrary SQL commands against the application database.

The vulnerability requires authentication to exploit, limiting the attack surface to users with valid credentials. However, once authenticated, an attacker could leverage the SQL injection to extract sensitive data, modify database contents, or potentially escalate privileges within the application. The vendor has released version 4.4.02_u06 to address the issue.

The vulnerability was responsibly disclosed by security researcher Kamil Dąbkowski and coordinated through CERT Polska's vulnerability disclosure process. Organizations running Simple.ERP should prioritize applying the patch to eliminate this attack vector.

## Mentioned in this report

- Vulnerabilities: CVE-2026-1198

Source reporting: https://cert.pl/en/posts/2026/02/CVE-2026-1198

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4129dccf-087b-5c0a-94af-d89f4a26bce3/simple-erp-sql-injection-fixed-in-update.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
