| CVE ID | CVE-2026-0809 |
| Publication date | 12 March 2026 |
| Vendor | Streamsoft |
| Product | Streamsoft Prestiż |
| Vulnerable versions | From 12.2.363.17 to 20.0.380.91 |
| Vulnerability type (CWE) | Weak Encoding for Password (CWE-261) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Streamsoft Prestiż software and participated in coordination of its disclosure.
The vulnerability CVE-2026-0809: Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know values are encoded. This issue was fixed in version 20.0.380.92.
Credits
We thank Kamil Dąbkowski for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.