Streamsoft Prestiż token flaw exposes Polish e-invoicing
A predictable token encoding vulnerability in Streamsoft Prestiż software allows attackers to guess KSeF e-invoicing system tokens, fixed in version 20.0.380.92.
CERT Polska coordinated the disclosure of CVE-2026-0809, a vulnerability in Streamsoft Prestiż software that affects the Polish National e-Invoice System (KSeF). The flaw stems from a custom token encoding algorithm that allows attackers to predict token values after analyzing encoded tokens with known values. This weakness could enable unauthorized access to the KSeF system by compromising authentication mechanisms.
The vulnerability was responsibly reported by researcher Kamil Dąbkowski and has been addressed by the vendor in version 20.0.380.92. Organizations using Streamsoft Prestiż for KSeF integration should update to the patched version immediately to prevent potential unauthorized access to e-invoicing data.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-0809
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free