# Streamsoft Prestiż token flaw exposes Polish e-invoicing

Published: 2026-03-12 · Severity: medium · Sectors: financial-services, government-national
Canonical: https://vorant.io/reports/5b54e9aa-46ff-5b6b-8086-c3c45835350a/streamsoft-presti-token-flaw-exposes-polish-e-invoicing

> A predictable token encoding vulnerability in Streamsoft Prestiż software allows attackers to guess KSeF e-invoicing system tokens, fixed in version 20.0.380.92.

CERT Polska coordinated the disclosure of CVE-2026-0809, a vulnerability in Streamsoft Prestiż software that affects the Polish National e-Invoice System (KSeF). The flaw stems from a custom token encoding algorithm that allows attackers to predict token values after analyzing encoded tokens with known values. This weakness could enable unauthorized access to the KSeF system by compromising authentication mechanisms.

The vulnerability was responsibly reported by researcher Kamil Dąbkowski and has been addressed by the vendor in version 20.0.380.92. Organizations using Streamsoft Prestiż for KSeF integration should update to the patched version immediately to prevent potential unauthorized access to e-invoicing data.

## Mentioned in this report

- Vulnerabilities: CVE-2026-0809

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-0809

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5b54e9aa-46ff-5b6b-8086-c3c45835350a/streamsoft-presti-token-flaw-exposes-polish-e-invoicing.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
