Junglewise Threat Intelligence

CVE-2026-11747: Seres Software syWEB reflected cross-site scripting

CVE-2026-11747 · Severity: medium · CVSS 6.1 · Published 2026-08-27

Technologies: Seres Software syWEB. Vendors: Seres Software.

Executive brief

Seres Software syWEB is a web application framework used to build business web applications. A reflected cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts into web pages viewed by users, potentially stealing session credentials, capturing user input, or redirecting users to fraudulent sites. The vendor has confirmed the product is no longer supported and will not receive patches.

Technical details

A reflected XSS vulnerability exists in Seres Software syWEB due to improper neutralization of user-supplied input during web page generation. An attacker can craft a malicious URL containing JavaScript code that, when clicked by a victim, executes in the context of the victim's browser session. No authentication is required, and the attack requires only that a user click a malicious link. An attacker can steal session cookies, perform actions on behalf of the user, or redirect to malicious content. Since the vendor confirmed the product is unsupported, no official patches are available; users should consider decommissioning the application or implementing compensating controls such as Web Application Firewalls.

Affected products

  • Seres Software syWEB through 27082026

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: advisory: CVE-2026-11747 published; vendor confirmed product is unsupported

References

Related threats