SQL Injection Patched in Simple.ERP
A coordinated disclosure fixed an authenticated SQL injection flaw in Simple.ERP's account turnover search feature.
CERT Polska coordinated the disclosure of CVE-2026-1198, a SQL injection vulnerability in Simple.ERP software. The flaw resides in the search functionality of the "Obroty na kontach" (account turnover) window, where insufficient input validation allows an authenticated attacker to execute arbitrary SQL commands against the underlying database.
The vendor has released a fix in version [email protected]_u06, addressing the issue. The vulnerability was reported responsibly by researcher Kamil Dąbkowski, and CERT Polska managed the coordinated vulnerability disclosure process. There is no indication of active exploitation in the wild; this is a standard patch advisory following responsible disclosure.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/02/CVE-2026-1198
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free