# Streamsoft Prestiż KSeF token flaw patched

Published: 2026-03-12 · Severity: low · Sectors: government-national
Canonical: https://vorant.io/reports/5b54e9aa-46ff-5b6b-8086-c3c45835350a/streamsoft-presti-ksef-token-flaw-patched

> A weak custom token encoding in Streamsoft Prestiż let attackers guess KSeF e-invoicing tokens; fixed in version 20.0.380.92.

CERT Polska coordinated the disclosure of a vulnerability in Streamsoft Prestiż, an accounting/ERP product used to interact with Poland's national e-invoicing system (KSeF). The flaw, tracked as CVE-2026-0809, stems from a custom token encoding algorithm that could allow an attacker to derive or predict valid KSeF authentication tokens by analyzing the encoding of known token values.

The vendor has released version 20.0.380.92 to remediate the issue. The report was submitted through CERT Polska's coordinated vulnerability disclosure process and credited to researcher Kamil Dąbkowski. There is no indication in the advisory of active exploitation in the wild; this is a responsible-disclosure notice with a vendor fix already available.

## Mentioned in this report

- Vulnerabilities: CVE-2026-0809

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-0809

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5b54e9aa-46ff-5b6b-8086-c3c45835350a/streamsoft-presti-ksef-token-flaw-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
