Description
Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to read and edit database content.

This vulnerability has been fixed in version: Finka-FK 18.5, Finka-KPR 16.6, Finka-Płace 13.4, Finka-Faktura 18.3, Finka-Magazyn 8.3, Finka-STW 12.3
Published: 2026-02-24
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 26 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Feb 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Finka
Finka finka-faktura
Finka finka-fk
Finka finka-kpr
Finka finka-magazyn
Finka finka-place
Finka finka-stw
CPEs cpe:2.3:a:finka:finka-faktura:*:*:*:*:*:*:*:*
cpe:2.3:a:finka:finka-fk:*:*:*:*:*:*:*:*
cpe:2.3:a:finka:finka-kpr:*:*:*:*:*:*:*:*
cpe:2.3:a:finka:finka-magazyn:*:*:*:*:*:*:*:*
cpe:2.3:a:finka:finka-place:*:*:*:*:*:*:*:*
cpe:2.3:a:finka:finka-stw:*:*:*:*:*:*:*:*
Vendors & Products Finka
Finka finka-faktura
Finka finka-fk
Finka finka-kpr
Finka finka-magazyn
Finka finka-place
Finka finka-stw
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Wed, 25 Feb 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Tik-soft
Tik-soft finka-faktura
Tik-soft finka-fk
Tik-soft finka-kpr
Tik-soft finka-magazyn
Tik-soft finka-płace
Tik-soft finka-stw
Vendors & Products Tik-soft
Tik-soft finka-faktura
Tik-soft finka-fk
Tik-soft finka-kpr
Tik-soft finka-magazyn
Tik-soft finka-płace
Tik-soft finka-stw

Tue, 24 Feb 2026 16:30:00 +0000

Type Values Removed Values Added
Description Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to read and edit database content. This vulnerability has been fixed in version: Finka-FK 18.5, Finka-KPR 16.6, Finka-Płace 13.4, Finka-Faktura 18.3, Finka-Magazyn 8.3, Finka-STW 12.3
Title Hard-coded database credentials in Finka software
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Finka Finka-faktura Finka-fk Finka-kpr Finka-magazyn Finka-place Finka-stw
Tik-soft Finka-faktura Finka-fk Finka-kpr Finka-magazyn Finka-płace Finka-stw
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-02-26T19:49:53.565Z

Reserved: 2025-11-28T12:37:10.698Z

Link: CVE-2025-13776

cve-icon Vulnrichment

Updated: 2026-02-26T19:49:39.828Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-24T17:29:02.023

Modified: 2026-02-26T19:38:41.043

Link: CVE-2025-13776

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-25T11:38:44Z

Weaknesses