CVE-2026-50641
HIGHPlaintext password storage in Streamsoft Business Intelligence
Title source: cnaDescription
Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login.
References (2)
Core 2
Core References
Third Party Advisory third-party-advisory
https://cert.pl/posts/2026/07/CVE-2026-50641
Product product
https://www.streamsoft.pl/business-intelligence/
Scores
CVSS v4
7.1
EPSS
0.0016
EPSS Percentile
5.7%
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-256
Status
published
Products (1)
Streamsoft/Business Intelligence
< 6.8.0.0
Published
Jul 29, 2026
Tracked Since
Jul 29, 2026