---
id: CVE-2025-68420
title: "Comarch\_ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in"
summary: "Comarch\_ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in. It is possible for a local attacker who controls the client process to dump it's memory, extra…"
severity: none
cwe:
  - CWE-266
published: '2026-05-14'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68420'
references:
  - url: 'https://cert.pl/posts/2026/05/CVE-2025-68420/'
    label: cvd@cert.pl
  - url: 'https://www.comarch.pl/erp/comarch-optima/'
    label: cvd@cert.pl
tags:
  - nvd
epss: 0.00114
epssPercentile: 0.01336
ingestedAt: '2026-09-30T22:27:27.792Z'
---

## Overview

Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in. It is possible for a local attacker who controls the client process to dump it's memory, extract credentials and use them to gain a privileged access to the database. In order to exploit this vulnerability, the client application has to be already configured, but a user does not have to be logged in. 
This issue has been fixed in version 2026.4

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
