Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know values are encoded.

This issue was fixed in version 20.0.380.92.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 12 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Mar 2026 13:15:00 +0000

Type Values Removed Values Added
Description Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know values are encoded. This issue was fixed in version 20.0.380.92.
Title Weak KSeF token encoding in Streamsoft Prestiż
Weaknesses CWE-261
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-03-12T14:04:53.073Z

Reserved: 2026-01-09T14:56:38.137Z

Link: CVE-2026-0809

cve-icon Vulnrichment

Updated: 2026-03-12T14:04:22.959Z

cve-icon NVD

Status : Received

Published: 2026-03-12T13:16:00.723

Modified: 2026-03-12T13:16:00.723

Link: CVE-2026-0809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses