216.73.216.197

CVE-2025-68420

· Published 14/05/2026 11:16 · Modified 14/05/2026 16:07

Labels: CVE-2025-68420 2026-05-14CVE-2025-68420CWE-266[email protected]

Essential information

Published
14/05/2026 11:16
Modified
14/05/2026 16:07
Author
Creator
CVSS
7.5 HIGH (v3) 7.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in. It is possible for a local attacker who controls the client process to dump it's memory, extract credentials and use them to gain a privileged access to the database. In order to exploit this vulnerability, the client application has to be already configured, but a user does not have to be logged in.  This issue has been fixed in version 2026.4

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
comarch / erp optima cpe:2.3:a:comarch:erp_optima:2026.4:*:*:*:*:*:*:*

References