# SQL Injection Patched in Simple.ERP

Published: 2026-02-26 · Severity: low
Canonical: https://vorant.io/reports/4129dccf-087b-5c0a-94af-d89f4a26bce3/sql-injection-patched-in-simple-erp

> A coordinated disclosure fixed an authenticated SQL injection flaw in Simple.ERP's account turnover search feature.

CERT Polska coordinated the disclosure of CVE-2026-1198, a SQL injection vulnerability in Simple.ERP software. The flaw resides in the search functionality of the "Obroty na kontach" (account turnover) window, where insufficient input validation allows an authenticated attacker to execute arbitrary SQL commands against the underlying database.

The vendor has released a fix in version [email protected]_u06, addressing the issue. The vulnerability was reported responsibly by researcher Kamil Dąbkowski, and CERT Polska managed the coordinated vulnerability disclosure process. There is no indication of active exploitation in the wild; this is a standard patch advisory following responsible disclosure.

## Mentioned in this report

- Vulnerabilities: CVE-2026-1198

Source reporting: https://cert.pl/en/posts/2026/02/CVE-2026-1198

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4129dccf-087b-5c0a-94af-d89f4a26bce3/sql-injection-patched-in-simple-erp.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
