cert.plThird-party advisory
https://cert.pl/posts/2026/02/CVE-2026-1198 CVE-2026-1198
HIGH
SQL Injection in SIMPLE.ERP
Record summary
CVE-2026-1198 has a selected CVSS score of 8.6 (high).
Description
SIMPLE.ERP is vulnerable to the SQL Injection in search functionality in "Obroty na kontach" window. Lack of input validation allows an authenticated attacker to prepare a malicious query to the database that will be executed. This issue was fixed in 6.30@A04.4_u06.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 26, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Simple.ERPBrowse Simple SA / Simple.ERPDefault status: unaffected | CVE List | Before 6.30@A04.4_u06 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-1198 simple.com.plproduct
https://simple.com.pl/