PatchSiren

Comarch CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Comarch CVE published 2026-05-14

CVE-2025-68421

CVE-2025-68421 involves a Comarch ERP Optima client using a hard-coded database user password that cannot be changed. This allows remote attackers to access the database with elevated privileges, including executing system commands on the server. The issue was fixed in version 2026.4. Defenders managing Comarch ERP Optima installations, especially those with remote database access, should assess their exp [truncated]

HIGH Comarch CVE published 2026-05-14

CVE-2025-68420

CVE-2025-68420 debrief based on the supplied source corpus. The Comarch ERP Optima client vulnerability allows local attackers to gain privileged database access. Defenders should assess exposure and verify patch status to mitigate potential data tampering or unauthorized access. The client application must be configured, but no user login is required for exploitation. This issue is fixed in version 2026. [truncated]