Simple.ERP software contains an SQL injection vulnerability (CVE-2026-1198) in the search…
Simple.ERP software contains an SQL injection vulnerability (CVE-2026-1198) in the search functionality of the 'Obroty na kontach' window, allowing authenticated attackers to execute arbitrary SQL commands.
CERT Polska has coordinated the disclosure of a SQL injection vulnerability in Simple.ERP software, tracked as CVE-2026-1198. The vulnerability exists in the search functionality within the 'Obroty na kontach' (Account Turnover) window, where inadequate input validation permits authenticated attackers to execute arbitrary SQL commands against the underlying database. This represents a classic SQL injection flaw that could allow an attacker with valid credentials to extract sensitive data, modify database contents, or potentially escalate privileges within the application.
The vulnerability was responsibly disclosed by security researcher Kamil Dąbkowski and has been addressed by the vendor in version [email protected]_u06. Organizations using Simple.ERP should prioritize patching to this version or later to remediate the issue. While exploitation requires authenticated access, the ability to execute arbitrary SQL commands poses significant risk to data confidentiality and integrity for affected deployments.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/02/CVE-2026-1198
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free