VORANT. Threat Intelligence Sign in Get the full feed

Streamsoft Prestiż token flaw exposes Polish e-invoicing

medium vulnerability financial-servicesgovernment-national

A predictable token encoding vulnerability in Streamsoft Prestiż software allows attackers to guess KSeF e-invoicing system tokens, fixed in version 20.0.380.92.

CERT Polska coordinated the disclosure of CVE-2026-0809, a vulnerability in Streamsoft Prestiż software that affects the Polish National e-Invoice System (KSeF). The flaw stems from a custom token encoding algorithm that allows attackers to predict token values after analyzing encoded tokens with known values. This weakness could enable unauthorized access to the KSeF system by compromising authentication mechanisms.

The vulnerability was responsibly reported by researcher Kamil Dąbkowski and has been addressed by the vendor in version 20.0.380.92. Organizations using Streamsoft Prestiż for KSeF integration should update to the patched version immediately to prevent potential unauthorized access to e-invoicing data.

Mentioned in this report

Vulnerabilities CVE-2026-0809

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-0809

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free