CVE-2026-0809
CVE-2026-0809: Weak custom token encoding in Streamsoft Prestiż allows attackers to predict KSeF e-invoice system tokens by analyzing encoded values; fixed in version 20.0.380.92.
CERT Polska disclosed a vulnerability in Streamsoft Prestiż software, identified as CVE-2026-0809. The flaw stems from the use of a custom token encoding algorithm that can be reverse-engineered to predict authentication tokens for Poland's national e-invoicing system (Krajowy System e-Faktur, or KSeF). An attacker who analyzes how tokens with known values are encoded can derive the logic and generate valid tokens, potentially gaining unauthorized access to the e-invoicing system.
The vulnerability was responsibly disclosed by Kamil Dąbkowski and coordinated through CERT Polska's disclosure process. Streamsoft addressed the issue in version 20.0.380.92 of Prestiż. Organizations using earlier versions should upgrade immediately to prevent token prediction attacks that could compromise access to sensitive financial and invoicing data.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-0809
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free