High severity7.1NVD Advisory· Published Feb 24, 2026· Updated Jun 17, 2026
CVE-2025-13776
CVE-2025-13776
Description
Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to read and edit database content.
This vulnerability has been fixed in version: Finka-FK 18.5, Finka-KPR 16.6, Finka-Płace 13.4, Finka-Faktura 18.3, Finka-Magazyn 8.3, Finka-STW 12.3
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15cpe:2.3:a:finka:finka-faktura:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:finka:finka-faktura:*:*:*:*:*:*:*:*range: <18.3
- (no CPE)range: 18.3
cpe:2.3:a:finka:finka-magazyn:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:finka:finka-magazyn:*:*:*:*:*:*:*:*range: <8.3
- (no CPE)range: 8.3
cpe:2.3:a:finka:finka-place:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:finka:finka-place:*:*:*:*:*:*:*:*range: <13.4
- (no CPE)range: 13.4
- Range: 0
- Range: 0
Patches
Vulnerability mechanics
References
2- cert.pl/en/posts/2026/01/CVE-2025-13776nvdBroken Link
- finka.plnvdProduct
News mentions
0No linked articles in our index yet.