# Streamsoft BI Stored Passwords in Plaintext

Published: 2026-07-29 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/331da519-31eb-5818-a0f9-5a4b2de377da/streamsoft-bi-stored-passwords-in-plaintext

> Streamsoft Business Intelligence stored user passwords in plaintext, fixed in version 6.8.0.0 via coordinated disclosure with CERT Polska.

CERT Polska coordinated the disclosure of a vulnerability in Streamsoft Business Intelligence (BI) software, tracked as CVE-2026-50641, in which user passwords were stored in plaintext within the application's database. Plaintext password storage is a significant security weakness because it exposes credentials to anyone with database access, whether through a separate compromise, insider threat, or backup exposure, and eliminates the protective barrier that proper hashing provides.

The vendor addressed the issue in version 6.8.0.0 and additionally required users to change their passwords upon first login following the update, mitigating the risk that previously exposed plaintext credentials could be reused by an attacker. The vulnerability was responsibly reported by researcher Kamil Dąbkowski and handled through CERT Polska's coordinated vulnerability disclosure process. There is no indication in the report of active exploitation in the wild.

## Mentioned in this report

- Vulnerabilities: CVE-2026-50641

Source reporting: https://cert.pl/en/posts/2026/07/CVE-2026-50641

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/331da519-31eb-5818-a0f9-5a4b2de377da/streamsoft-bi-stored-passwords-in-plaintext.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
