CVE-2026-11754 MEDIUM

CVE-2026-11754: User Enumeration in Seres Software's syWEB

Vendor Seres Software
Product syWEB
Weakness CWE-203
Published August 27, 2026
Last update August 27, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting. This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned that the product is not supported.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 27, 2026 Record updated