Sensitive Information Exposure in Streamsoft Business Intelligence Software
CVE-2026-50641

7.1HIGH

Key Information:

Vendor

Streamsoft

Vendor
CVE Published:
29 July 2026

What is CVE-2026-50641?

The Streamsoft Business Intelligence software contains a significant vulnerability that allows user passwords to be stored in plaintext within its database. This design flaw poses a severe risk, as it may enable unauthorized access to user accounts. The issue has been addressed in version 6.8.0.0, where users are urged to change their passwords upon their first login following the upgrade. Organizations relying on this software should prioritize updating to the latest version to enhance security measures.

Affected Version(s)

Business Intelligence 0 < 6.8.0.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamil DÄ…bkowski
.