CVE-2026-11747: Reflected XSS in Seres Software's syWEB
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Seres Software syWEB allows Reflected XSS.
This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned that the product is not supported.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attack is network-reachable, requires no privileges, and has low attack complexity. However, it requires user interaction, such as causing a victim to load a crafted request or page.
What is the likely impact if exploitation succeeds?
Successful exploitation can affect confidentiality and integrity at a low level, with impacts extending beyond the vulnerable component because the scope is changed. No availability impact is listed.
Is a vendor patch likely to be available?
The product is reported as unsupported by the vendor. Organizations using syWEB should plan compensating controls or migration rather than relying on a vendor-supported fix.