| CVE ID | CVE-2026-1198 |
| Publication date | 26 February 2026 |
| Vendor | Simple SA |
| Product | Simple.ERP |
| Vulnerable versions | All before [email protected]_u06 |
| Vulnerability type (CWE) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Simple.ERP software and participated in coordination of its disclosure.
The vulnerability CVE-2026-1198: SIMPLE.ERP is vulnerable to the SQL Injection in search functionality in "Obroty na kontach" window. Lack of input validation allows an authenticated attacker to run arbitrary SQL commands.
This issue was fixed in version [email protected]_u06.
Credits
We thank Kamil Dąbkowski for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.