---
id: CVE-2025-68421
title: >-
  Comarch ERP Optima client makes use of a hard-coded password for a database
  user
summary: >-
  Comarch ERP Optima client makes use of a hard-coded password for a database
  user. These credentials cannot be changed. It is possible for a remote
  attacker to gain an access to the database with elevated privileges including
  executing sy…
severity: none
cwe:
  - CWE-798
published: '2026-05-14'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68421'
references:
  - url: 'https://cert.pl/posts/2026/05/CVE-2025-68420/'
    label: cvd@cert.pl
  - url: 'https://www.comarch.pl/erp/comarch-optima/'
    label: cvd@cert.pl
tags:
  - nvd
epss: 0.00229
epssPercentile: 0.12397
ingestedAt: '2026-09-30T22:27:27.793Z'
---

## Overview

Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elevated privileges including executing system commands on a server.
This issue has been fixed in version 2026.4

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
