| CVE ID | CVE-2026-50641 |
| Publication date | 29 July 2026 |
| Vendor | Streamsoft |
| Product | Business Intelligence |
| Vulnerable versions | All before 6.8.0.0 |
| Vulnerability type (CWE) | Plaintext Storage of a Password (CWE-256) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Streamsoft Business Intelligence software and participated in coordination of its disclosure.
The vulnerability CVE-2026-50641: Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database.
This issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login.
Credits
We thank Kamil Dąbkowski for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.