Description
Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database

This issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login.
Published: 2026-07-29
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Streamsoft Business Intelligence stores user passwords in plaintext within its database. This flaw allows any actor with database read access to obtain clear‑text passwords, compromising account authenticity and potentially exposing users to credential reuse attacks. The vulnerability is recognized as CWE‑256.

Affected Systems

All instances of Streamsoft Business Intelligence released before version 6.8.0.0 are affected. The issue was fixed in version 6.8.0.0. Users are encouraged to upgrade to the newest release.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact severity; however, the EPSS of less than 1% and absence from CISA KEV suggest that exploitation is unlikely at present. An attacker must gain database access or exploit another vulnerability to read the credentials, but once achieved, the data exposure could compromise multiple user accounts.

Generated by OpenCVE AI on August 2, 2026 at 07:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Streamsoft Business Intelligence to version 6.8.0.0 or later
  • Enforce password change on first login after upgrade
  • Implement stricter database access controls and monitor for unauthorized reads

Generated by OpenCVE AI on August 2, 2026 at 07:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Streamsoft
Streamsoft business Intelligence
Vendors & Products Streamsoft
Streamsoft business Intelligence

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login.
Title Plaintext password storage in Streamsoft Business Intelligence
Weaknesses CWE-256
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Streamsoft Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-07-29T14:18:45.698Z

Reserved: 2026-06-05T13:27:10.270Z

Link: CVE-2026-50641

cve-icon Vulnrichment

Updated: 2026-07-29T14:18:34.833Z

cve-icon NVD

Status : Deferred

Published: 2026-07-29T13:18:53.053

Modified: 2026-07-30T19:11:24.687

Link: CVE-2026-50641

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T08:00:04Z

Weaknesses
  • CWE-256

    Plaintext Storage of a Password