Streamsoft Prestiż KSeF token flaw patched
A weak custom token encoding in Streamsoft Prestiż let attackers guess KSeF e-invoicing tokens; fixed in version 20.0.380.92.
CERT Polska coordinated the disclosure of a vulnerability in Streamsoft Prestiż, an accounting/ERP product used to interact with Poland's national e-invoicing system (KSeF). The flaw, tracked as CVE-2026-0809, stems from a custom token encoding algorithm that could allow an attacker to derive or predict valid KSeF authentication tokens by analyzing the encoding of known token values.
The vendor has released version 20.0.380.92 to remediate the issue. The report was submitted through CERT Polska's coordinated vulnerability disclosure process and credited to researcher Kamil Dąbkowski. There is no indication in the advisory of active exploitation in the wild; this is a responsible-disclosure notice with a vendor fix already available.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-0809
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free