Junglewise Threat Intelligence

CVE-2026-25608: CIOP-PIB STER cleartext transmission of sensitive information

CVE-2026-25608 · Severity: info · CVSS 2.3 · Published 2026-05-22

Technologies: Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy (CIOP-PIB) STER.

Executive brief

STER, a software suite used for occupational health and safety management, transmits data over the network using unencrypted TCP traffic. This allows an attacker positioned on the same network to intercept sensitive information, including user passwords, personal data, and authentication tokens. Such an exploit could lead to unauthorized account access and the exposure of confidential employee or organizational records.

Technical details

The STER application suffers from cleartext transmission of sensitive information (CWE-319) due to the use of unencrypted TCP traffic for network communications. An attacker with the ability to intercept network traffic (e.g., via a Man-in-the-Middle position) can capture sensitive data such as passwords and authentication tokens in plain text. This vulnerability affects all versions of the software prior to 9.5. The issue is resolved in version 9.5, which likely introduces encryption for data in transit.

Affected products

  • Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy (CIOP-PIB) STER All versions prior to 9.5

Timeline

  • 2026-05-22: advisory: Advisory published by CERT.PL and NVD
  • 2026-05-22: patched: Fix released in version 9.5

References