CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligence

CVE-2026-50641 (TL-2026-1825) is a high-severity software vulnerability scored CVSS 7.1, first published 2026-08-03. It has no confirmed attribution, affects Streamsoft Business Intelligence, references 1 CVE (CVE-2026-50641), maps to 14 MITRE ATT&CK techniques (T1021, T1021.001, T1021.002), and is covered by 9 detection rules and 32 indicators of compromise.

Key facts for TL-2026-1825

Threat ID
TL-2026-1825
Severity
HIGH
CVSS
7.1 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
Status
PATCHED
Category
VULNERABILITY
First published
2026-08-03
Last reviewed
2026-08-03
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
manufacturing, logistics, finance, professional services, erp customers
Target regions
poland, Europe
Detection rules
9
Indicators of compromise
32

Streamsoft Business Intelligence (BI) versions prior to 6.8.0.0 store user passwords in plaintext in the application database (CWE-256, CVSS v4.0 7.1 HIGH). CERT Polska coordinated the disclosure with reporter Kamil Dąbkowski; Streamsoft fixed the issue in 6.8.0.0 and requires affected users to change their password on first login after upgrading.

How CVE-2026-50641 works

Streamsoft Business Intelligence (BI) is the analytics/reporting module Streamsoft, a Polish ERP vendor headquartered in Zielona Góra, bundles into its two flagship ERP product lines: Streamsoft Verto (cloud-based) and Streamsoft Prestiż (on-premise, Windows/Linux). The BI module aggregates cross-departmental operational data spanning production, logistics, and finance for reporting and analytics, meaning its own account database is a high-value target independent of the core ERP credential store.

CERT Polska (operated by NASK) disclosed CVE-2026-50641 on 2026-07-29 after coordinating with researcher Kamil Dąbkowski, who reported that all Streamsoft BI versions prior to 6.8.0.0 store user account passwords in cleartext in the underlying application database (CWE-256: Plaintext Storage of a Password, a base-level child of CWE-522: Insufficiently Protected Credentials, which is itself a child of CWE-668: Exposure of Resource to Wrong Sphere and CWE-1390: Weak Authentication). No password hashing or encryption at rest is applied to the credential table. MITRE's CWE-256 entry rates the likelihood of exploit for this weakness class as HIGH and notes it is reliably identifiable by automated SAST tooling; per CWE guidance, any actor who obtains read access to the database — via a separate SQL injection flaw, a stolen or misconfigured backup, insider access, or an exposed database service — recovers every affected user's live, working password in immediately usable form, rather than a hash requiring offline cracking.

NVD scored the flaw CVSS v4.0 7.1 (HIGH): AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N (no CVSS v3.1 vector was assessed). The Adjacent (AV:A) attack vector indicates the vulnerable component is reached from an adjacent network segment rather than the open internet, consistent with Streamsoft BI's typical on-premise/internal-LAN deployment alongside Prestiż. The vector reflects only the confidentiality impact of the exposed credential store itself (VC:H); it does not model the downstream impact of an attacker reusing the harvested plaintext credentials elsewhere, which is the primary real-world risk given common password reuse between BI, ERP, and Active Directory accounts in SME environments. NVD's associated CISA Authorized Data Publisher (ADP) SSVC assessment, recorded the same day as publication (2026-07-29), rated exploitation likelihood as "none" and technical impact as "partial" — consistent with the absence of any known PoC or in-the-wild exploitation.

CERT Polska reserved the CVE on 2026-06-05 and published the coordinated advisory on 2026-07-29, alongside the CVE.org record and NVD ingestion the same day; NVD's record was last modified 2026-07-30. No proof-of-concept exploit code, in-the-wild exploitation, or known IOCs/adversary campaign have been reported by any source — CVE-2026-50641 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog as of this research. Streamsoft had already shipped the fix (version 6.8.0.0) by the time of public disclosure and mandated a forced password reset on next login for upgraded customers, which neutralizes any plaintext passwords an attacker may have already harvested prior to the upgrade.

**Vendor pattern — recurring credential/input-handling weaknesses.** CVE-2026-50641 is the fourth CERT Polska-coordinated vulnerability disclosure against Streamsoft's ERP product line in roughly 16 months, and the fourth reported by the same researcher, Kamil Dąbkowski. On 2025-03-28, CERT Polska jointly disclosed two Streamsoft Prestiż flaws Dąbkowski reported: CVE-2024-7407 (CWE-261, Weak Encoding for Password — passwords encoded with a reversible algorithm from which the original credential can be recovered by observing the encoding process, fixed in 18.2.377) and CVE-2024-11504 (CWE-89, SQL Injection — unsanitized user-entered fields exploitable by an authenticated low-privilege account, CVSS v4.0 8.6 HIGH, fixed in 18.1.376.37). On 2026-03-12, CERT Polska disclosed CVE-2026-0809 (CWE-261 again — a custom token-encoding algorithm in Streamsoft Prestiż allows the KSeF e-invoicing (Krajowy System e-Faktur) token value to be guessed by analyzing tokens with known values, affecting 12.2.363.17 through 20.0.380.91, fixed in 20.0.380.92). Taken together, these four CVEs show a consistent vendor-level pattern of weak/reversible credential and token protection (CWE-261, CWE-256) compounded by insufficient input validation (CWE-89) across both the Prestiż and BI product lines, which should inform risk scoring of any other undisclosed Streamsoft component.

**Related attack patterns (CAPEC).** MITRE's CWE-522 (parent of CWE-256) cross-references several CAPEC attack patterns describing how adversaries operationalize insufficiently protected credentials once obtained: CAPEC-102 (Session Sidejacking), CAPEC-600 (Credential Stuffing), CAPEC-644 (Use of Captured Hashes / Pass the Hash), CAPEC-560 (Use of Known Domain Credentials), CAPEC-652 (Use of Known Kerberos Credentials), and CAPEC-653 (Use of Known Operating System Credentials). These describe the generic post-harvest abuse patterns applicable to any plaintext credential exposure, including this one, rather than techniques specific to Streamsoft BI.

MITRE ATT&CK techniques used in TL-2026-1825

Lateral Movement

T1021 Remote Services; T1021.001 Remote Desktop Protocol; T1021.002 SMB/Windows Admin Shares; T1021.004 SSH

Initial Access

T1078 Valid Accounts; T1078.003 Local Accounts; T1078.004 Cloud Accounts; T1190 Exploit Public-Facing Application

Persistence

T1078 Valid Accounts

Privilege Escalation

T1078 Valid Accounts

Defense Evasion

T1078 Valid Accounts

Discovery

T1087 Account Discovery; T1087.001 Local Account; T1087.004 Cloud Account

Credential Access

T1110.004 Credential Stuffing; T1552 Unsecured Credentials

Collection

T1213 Data from Information Repositories

Affected products and versions in CVE-2026-50641

  • Streamsoft — Business Intelligence
    Vulnerable versions: < 6.8.0.0
    Fixed in: 6.8.0.0

Remediation for CVE-2026-50641

Patches

  • Streamsoft Business Intelligence 6.8.0.0 — remediates CWE-256 by removing plaintext password storage.

Immediate actions

  • Upgrade Streamsoft Business Intelligence to version 6.8.0.0 or later immediately.
  • Force a password reset for every BI account on upgrade (Streamsoft's mandated first-login reset neutralizes previously-harvested plaintext credentials).
  • Audit for password reuse between Streamsoft BI accounts and other systems (Streamsoft Verto/Prestiż ERP, Active Directory, VPN) and force resets anywhere reuse is found.
  • Restrict network access to the BI database/application to trusted adjacent-network hosts only, consistent with the CVSS AV:A (Adjacent) attack vector.
  • Given Streamsoft's recurring credential/encoding weaknesses (CVE-2024-7407, CVE-2024-11504, CVE-2026-0809), also verify Prestiż is patched to 20.0.380.92+ and 18.2.377+/18.1.376.37+ where those modules are in use.

Workarounds

  • None published; no interim mitigation exists short of upgrading to 6.8.0.0 — restrict network/database access to reduce exposure until patched.

Longer-term hardening

  • Deploy database activity monitoring / audit logging on the BI credential table to detect anomalous bulk-read access.
  • Adopt a policy requiring salted cryptographic password hashing (e.g., bcrypt/argon2) for all future in-house and third-party application credential stores.
  • Include CWE-256/CWE-522/CWE-261 checks in vendor security-assessment questionnaires for future ERP/BI procurement, given this vendor's disclosure history.
  • Monitor CERT Polska and NVD for further Streamsoft advisories given the observed four-CVE pattern in the vendor's ERP suite since 2025.

CVEs associated with CVE-2026-50641

CVE-2026-50641

Weaknesses (CWE) in CVE-2026-50641

CWE-256, CWE-522

Timeline of CVE-2026-50641

  • CERT Polska jointly disclosed CVE-2024-7407 (CWE-261 weak/reversible password encoding) and CVE-2024-11504 (CWE-89 SQL injection) in Streamsoft Prestiż, both reported by the same researcher, Kamil Dąbkowski, who later reported CVE-2026-50641 — the first evidence of a recurring credential/input-handling weakness pattern at this vendor.
  • CERT Polska disclosed CVE-2026-0809 (CWE-261) in Streamsoft Prestiż, a custom KSeF e-invoicing token encoding algorithm that allows token values to be guessed; also reported by Kamil Dąbkowski, fixed in 20.0.380.92 — the third related vendor disclosure ahead of CVE-2026-50641.
  • CVE-2026-50641 formally reserved by CERT Polska (CNA), marking the start of coordinated vulnerability disclosure handling for the Streamsoft BI plaintext-password-storage flaw reported by researcher Kamil Dąbkowski.
  • CISA (as an NVD Authorized Data Publisher) recorded an SSVC assessment for CVE-2026-50641 rating exploitation likelihood as "none" and technical impact as "partial", and the flaw was not added to the CISA Known Exploited Vulnerabilities (KEV) catalog.
  • National Vulnerability Database (NVD) ingested and published CVE-2026-50641, mirroring the CERT Polska CWE-256 classification and CVSS v4.0 vector.
  • CVE-2026-50641 published in the official CVE record by CERT Polska (assigner), with CVSS v4.0 base score 7.1 (HIGH).
  • CERT Polska publicly published the coordinated advisory for CVE-2026-50641 (English and Polish), crediting Kamil Dąbkowski for discovery and reporting.
  • Streamsoft Business Intelligence 6.8.0.0 shipped, remediating CWE-256; affected customers are required to change their password on first login after upgrading.
  • NVD record for CVE-2026-50641 last modified, one day after initial publication.

Sources cited for CVE-2026-50641

Threats related to CVE-2026-50641

Detection coverage for TL-2026-1825

As of 2026-08-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1825 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats