CVE-2025-68421EPSS p12.5%
CVE-2025-68421CVE-2025-68421
Description
Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elevated privileges including executing system commands on a server.
This issue has been fixed in version 2026.4
Scoring
| EPSS | 0.23% probability of exploitation · percentile 12.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |