Junglewise Threat Intelligence

CVE-2025-68420: Comarch ERP Optima incorrect privilege assignment in database connection

CVE-2025-68420 · Severity: info · CVSS 7.5 · Published 2026-05-14

Executive brief

Comarch ERP Optima is a business management software used for accounting, HR, and payroll. A security flaw allows a local attacker with access to a computer running the software to extract high-level database credentials from the application's memory. This could lead to unauthorized access to sensitive company financial and employee data, even if the attacker does not have a valid login for the application itself.

Technical details

The Comarch ERP Optima client suffers from an incorrect privilege assignment (CWE-266) where it establishes database connections using a high-privileged account by default. A local attacker who can control or inspect the client process can perform a memory dump to extract these database credentials. This extraction is possible as long as the client is configured, even if no user is currently logged into the application. Successful exploitation grants the attacker direct, privileged access to the underlying database, bypassing application-level access controls. The issue is resolved in version 2026.4.

Affected products

  • Comarch ERP Optima All versions prior to 2026.4

Timeline

  • 2026-05-14: disclosed: Advisory published by CERT.PL
  • 2026-05-14: patched: Fixed in version 2026.4

References

Related threats