CVE-2026-11754: User Enumeration in Seres Software's syWEB
Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting.
This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned that the product is not supported.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The vector is network-accessible and requires no privileges or user interaction. An unauthenticated remote party can use the observable discrepancy to determine whether accounts exist.
What security impact is documented?
The documented impact is limited confidentiality loss through account footprinting or user enumeration. No integrity or availability impact is listed.
Are supported fixes likely to be available?
The vendor stated that syWEB is not supported. Organizations using affected deployments should plan compensating controls or migration rather than relying on vendor support.
What versions are affected?
The issue is reported as affecting syWEB through 27082026. No fixed version is provided.