CVE-2026-0809: Streamsoft Prestiż

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know values are encoded. This issue was fixed in version 20.0.380.92.

Affected products

  • Streamsoft Streamsoft Prestiż: from 12.2.363.17, before 20.0.380.92 (fixed in 20.0.380.92)

Published 2026-03-12. Last modified 2026-06-17.