CVE detail
CVE-2025-13776 — CVE-2025-13776
Published 2026-02-24 · Modified 2026-06-17 · Vendor finka · Product finka-faktura · Source nvd
HIGH
severity
CVSS-derived band
0.0015
EPSS probability
exploitation probability, 30d
5.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to read and edit database content.
This vulnerability has been fixed in version: Finka-FK 18.5, Finka-KPR 16.6, Finka-Płace 13.4, Finka-Faktura 18.3, Finka-Magazyn 8.3, Finka-STW 12.3
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References