Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in. It is possible for a local attacker who controls the client process to dump it's memory, extract credentials and use them to gain a privileged access to the database. In order to exploit this vulnerability, the client application has to be already configured, but a user does not have to be logged in.
This issue has been fixed in version 2026.4
CVSS
No CVSS.
References
Configurations
No configuration.
History
14 May 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-14 11:16
Updated : 2026-05-14 16:07
NVD link : CVE-2025-68420
Mitre link : CVE-2025-68420
CVE.ORG link : CVE-2025-68420
JSON object : View
Products Affected
No product.
CWE
CWE-266
Incorrect Privilege Assignment
