CVE-2026-44629: High severity Synergis Streamvault all-in-one appliances (SV-100E series) vulnerability
Published Aug 27, 2026
·Updated
Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers.
Affected Software
3 affected components
Synergis Streamvault all-in-one appliances (SV-100E series)
Synergis Streamvault all-in-one appliances (SV-300E series)
Synergis Synergis Softwire
Event History
Aug 27, 2026
CVE Published
via MITRE·10:08 PM
Data Sourced
via MITRE·10:08 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
Exploitation requires local access and low privileges. No user interaction is required.
2
Which deployments should be prioritized for review?
Review Streamvault all-in-one appliances in the SV-100E and SV-300E series, along with Windows servers running Synergis Softwire.
3
What security impact could exploitation have?
The vulnerability is rated high severity with high confidentiality impact and low integrity and availability impact. The CVSS vector also indicates scope can change.
4
Which releases address the vulnerability?
The provided vendor references identify the issue as resolved in Synergis Softwire 12.0.2 and 12.2.0.