Hard-Coded Database Credentials in Finka Programs Expose Sensitive Data
CVE-2025-13776

8.6HIGH

Key Information:

Vendor

Tik-soft

Vendor
CVE Published:
24 February 2026

What is CVE-2025-13776?

Finka programs are susceptible to a credentials exposure vulnerability due to hard-coded Firebird database credentials shared across all instances. This flaw allows a malicious actor on the local network who is aware of these default credentials to manipulate or extract sensitive database content. This raises significant risks for organizations relying on these products, as unauthorized access can lead to data breaches and integrity issues.

Affected Version(s)

Finka-Faktura 0 < 18.3

Finka-FK 0 < 18.5

Finka-KPR 0 < 16.6

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wojciech Żebrowski (Wern128)
.