Executive brief
Comarch ERP Optima is a popular business management software used for accounting, HR, and payroll. A security flaw exists where the software uses a permanent, unchangeable password for database access. An attacker could use these credentials to gain full access to the company's financial and employee records, and potentially take control of the server hosting the database.
Technical details
The Comarch ERP Optima client utilizes hard-coded credentials (CWE-798) for a database user account. Because these credentials are static and cannot be modified by administrators, an attacker with network access to the database server can authenticate with elevated privileges. This access allows for full data exfiltration or modification, and specifically enables the execution of arbitrary system commands on the underlying server. The vulnerability is resolved in version 2026.4.
Affected products
- Comarch ERP Optima All versions prior to 2026.4
Timeline
- 2026-05-14: disclosed: Advisory published by CERT.PL
- 2026-05-14: patched: Fixed in version 2026.4