Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know values are encoded.

This issue was fixed in version 20.0.380.92.

Project Subscriptions

Vendors Products
Streamsoft Subscribe
Streamsoft Prestiż Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 13 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Streamsoft
Streamsoft streamsoft Prestiż
Vendors & Products Streamsoft
Streamsoft streamsoft Prestiż

Thu, 12 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Mar 2026 13:15:00 +0000

Type Values Removed Values Added
Description Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know values are encoded. This issue was fixed in version 20.0.380.92.
Title Weak KSeF token encoding in Streamsoft Prestiż
Weaknesses CWE-261
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-03-12T14:04:53.073Z

Reserved: 2026-01-09T14:56:38.137Z

Link: CVE-2026-0809

cve-icon Vulnrichment

Updated: 2026-03-12T14:04:22.959Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-12T13:16:00.723

Modified: 2026-03-12T21:07:53.427

Link: CVE-2026-0809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-13T09:53:11Z

Weaknesses