{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-50641","assignerOrgId":"4bb8329e-dd38-46c1-aafb-9bf32bcb93c6","state":"PUBLISHED","assignerShortName":"CERT-PL","dateReserved":"2026-06-05T13:27:10.270Z","datePublished":"2026-07-29T12:37:58.532Z","dateUpdated":"2026-07-29T14:18:45.698Z"},"containers":{"cna":{"providerMetadata":{"orgId":"4bb8329e-dd38-46c1-aafb-9bf32bcb93c6","shortName":"CERT-PL","dateUpdated":"2026-07-29T12:43:19.828Z"},"title":"Plaintext password storage in Streamsoft Business Intelligence","datePublic":"2026-07-29T00:00:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-256","description":"CWE-256 Plaintext Storage of a Password","type":"CWE"}]}],"affected":[{"vendor":"Streamsoft","product":"Business Intelligence","versions":[{"status":"affected","version":"0","lessThan":"6.8.0.0","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database\n\nThis issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login.","supportingMedia":[{"type":"text/html","base64":false,"value":"Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database<br><br>This issue was fixed in version&nbsp;6.8.0.0, users were also requested to change their password on the first login.<br>"}]}],"references":[{"url":"https://cert.pl/posts/2026/07/CVE-2026-50641","tags":["third-party-advisory"]},{"url":"https://www.streamsoft.pl/business-intelligence/","tags":["product"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"HIGH","baseScore":7.1,"vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}}],"credits":[{"lang":"en","value":"Kamil Dąbkowski","type":"finder"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-29T14:18:12.306816Z","id":"CVE-2026-50641","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-29T14:18:45.698Z"}}]}}