VORANT. Threat Intelligence Sign in Get the full feed

Comarch ERP Optima hardcoded DB credential flaws

medium vulnerability

Comarch ERP Optima had two vulnerabilities allowing credential theft and remote database compromise via a hardcoded account, now patched in version 2026.4.

CERT Polska coordinated disclosure of two vulnerabilities in Comarch ERP Optima, an enterprise resource planning client used by businesses. CVE-2025-68420 stems from the client connecting to its backend database using a high-privileged account regardless of the logged-in application user; a local attacker with access to the client process could dump memory to extract these database credentials, requiring only that the client be configured (not necessarily logged in). CVE-2025-68421 is more severe: the client uses a hard-coded database password that cannot be changed, allowing a remote attacker to authenticate to the database with elevated privileges, including the ability to execute system commands on the server.

Both issues were fixed in Comarch ERP Optima version 2026.4. There is no indication of active exploitation in the wild; this is a responsibly disclosed vulnerability report credited to researcher Wojciech Giełda, handled through CERT Polska's coordinated vulnerability disclosure process. Organizations running affected versions should prioritize patching, as the hard-coded credential (CVE-2025-68421) presents a straightforward path to remote database and potential server compromise.

Mentioned in this report

Vulnerabilities CVE-2025-68420CVE-2025-68421

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2025-68420

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free