# CVE-2026-50641

## Summary

- **CVE ID:** CVE-2026-50641
- **Severity:** HIGH
- **CVSS Score:** 7.1 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-256
- **Published:** Jul 29, 2026
- **Last Modified:** Jul 29, 2026

## Description

Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database

This issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login.

## Affected Products

- Streamsoft — Business Intelligence (0)

## References

- [CNA](https://cert.pl/posts/2026/07/CVE-2026-50641)
- [CNA](https://www.streamsoft.pl/business-intelligence/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._