{"id":"CVE-2025-68421","title":"Comarch ERP Optima client makes use of a hard-coded password for a database user","summary":"Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elevated privileges including executing sy…","severity":"none","cwe":["CWE-798"],"published":"2026-05-14","updated":"2026-09-30","sourceUpdated":"2026-09-30T22:10:00.273","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-68421","references":[{"url":"https://cert.pl/posts/2026/05/CVE-2025-68420/","label":"cvd@cert.pl"},{"url":"https://www.comarch.pl/erp/comarch-optima/","label":"cvd@cert.pl"}],"tags":["nvd"],"epss":0.00229,"epssPercentile":0.12397,"ingestedAt":"2026-09-30T22:27:27.793Z","slug":"CVE-2025-68421","body":"## Overview\n\nComarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elevated privileges including executing system commands on a server.\nThis issue has been fixed in version 2026.4\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}