CVE-2026-50641 Details
Description
Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login.
A vulnerability exists in Streamsoft Business Intelligence (BI) versions prior to 6.8.0.0, where user passwords are stored in plaintext in the database. This issue has been addressed in version 6.8.0.0, and users were advised to change their passwords upon their first login after the update.
Users can update to Streamsoft Business Intelligence version 6.8.0.0 or later to address this vulnerability. After updating, it is recommended to change passwords on the first login.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 29, 2026CISA-ADP
Assessed Jul 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/07/CVE-2026-50641 | [email protected] | AdvisoryRemedy |
| https://www.streamsoft.pl/business-intelligence/ | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-256 | Plaintext Storage of a Password | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Streamsoft Business Intelligence | < 6.8.0.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 29, 2026 | CVE Modified | CISA-ADP |
| Jul 29, 2026 | New CVE Received | [email protected] |
Volerion