# Comarch ERP Optima hardcoded DB credential flaws

Published: 2026-05-14 · Severity: medium
Canonical: https://vorant.io/reports/d0505eff-fc5d-5ea8-a3bb-3b7d2840a904/comarch-erp-optima-hardcoded-db-credential-flaws

> Comarch ERP Optima had two vulnerabilities allowing credential theft and remote database compromise via a hardcoded account, now patched in version 2026.4.

CERT Polska coordinated disclosure of two vulnerabilities in Comarch ERP Optima, an enterprise resource planning client used by businesses. CVE-2025-68420 stems from the client connecting to its backend database using a high-privileged account regardless of the logged-in application user; a local attacker with access to the client process could dump memory to extract these database credentials, requiring only that the client be configured (not necessarily logged in). CVE-2025-68421 is more severe: the client uses a hard-coded database password that cannot be changed, allowing a remote attacker to authenticate to the database with elevated privileges, including the ability to execute system commands on the server.

Both issues were fixed in Comarch ERP Optima version 2026.4. There is no indication of active exploitation in the wild; this is a responsibly disclosed vulnerability report credited to researcher Wojciech Giełda, handled through CERT Polska's coordinated vulnerability disclosure process. Organizations running affected versions should prioritize patching, as the hard-coded credential (CVE-2025-68421) presents a straightforward path to remote database and potential server compromise.

## Mentioned in this report

- Vulnerabilities: CVE-2025-68420, CVE-2025-68421

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2025-68420

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d0505eff-fc5d-5ea8-a3bb-3b7d2840a904/comarch-erp-optima-hardcoded-db-credential-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
