Junglewise Threat Intelligence

CVE-2026-50641: Streamsoft Business Intelligence plaintext password storage

CVE-2026-50641 · Severity: info · CVSS 7.1 · Published 2026-07-29

Executive brief

Streamsoft Business Intelligence, a platform used for advanced business analytics and data reporting, was found to store user passwords in an unencrypted, plaintext format within its database. If an unauthorized individual gains access to the database, they could immediately view and use all user credentials to compromise the system or perform identity theft. This poses a significant risk to data confidentiality and corporate operations.

Technical details

Streamsoft Business Intelligence (BI) versions prior to 6.8.0.0 suffer from a plaintext storage of passwords vulnerability (CWE-256). The application fails to use cryptographic hashing or encryption when storing user credentials in the backend database. An attacker with adjacent network access or local database access could retrieve all user passwords without needing to perform decryption or cracking. This issue was addressed in version 6.8.0.0, which introduces proper password handling; however, existing users must change their passwords upon their first login to the updated version to ensure the new security measures are applied to their credentials.

Affected products

  • Streamsoft Business Intelligence All versions prior to 6.8.0.0

Timeline

  • 2026-07-29: disclosed: Vulnerability disclosed by CERT.PL
  • 2026-07-29: patched: Fixed in version 6.8.0.0
  • 2026-07-29: advisory

References