# CVE-2026-0809

Published: 2026-03-12 · Severity: high · Sectors: financial-services
Canonical: https://vorant.io/reports/2efda0b6-d05b-452c-827f-8a6adc7509c3/cve-2026-0809

> CVE-2026-0809: Weak custom token encoding in Streamsoft Prestiż allows attackers to predict KSeF e-invoice system tokens by analyzing encoded values; fixed in version 20.0.380.92.

CERT Polska disclosed a vulnerability in Streamsoft Prestiż software, identified as CVE-2026-0809. The flaw stems from the use of a custom token encoding algorithm that can be reverse-engineered to predict authentication tokens for Poland's national e-invoicing system (Krajowy System e-Faktur, or KSeF). An attacker who analyzes how tokens with known values are encoded can derive the logic and generate valid tokens, potentially gaining unauthorized access to the e-invoicing system.

The vulnerability was responsibly disclosed by Kamil Dąbkowski and coordinated through CERT Polska's disclosure process. Streamsoft addressed the issue in version 20.0.380.92 of Prestiż. Organizations using earlier versions should upgrade immediately to prevent token prediction attacks that could compromise access to sensitive financial and invoicing data.

## Mentioned in this report

- Vulnerabilities: CVE-2026-0809

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-0809

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2efda0b6-d05b-452c-827f-8a6adc7509c3/cve-2026-0809.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
