Executive brief
Seres syWEB is a web application platform used to manage software services. This vulnerability allows attackers to detect the existence or non-existence of user accounts through observable differences in system responses, enabling account enumeration without requiring authentication. This can facilitate unauthorized account discovery and targeted phishing or brute-force attacks.
Technical details
The vulnerability is an observable discrepancy (information disclosure) flaw in syWEB that enables account footprinting. The application returns different responses when queried about valid versus invalid user accounts, allowing unauthenticated attackers to enumerate existing accounts via the network. This is a reconnaissance technique that does not directly compromise user data but significantly lowers the barrier to subsequent account compromise attacks. The vendor confirmed the product is no longer supported and will not receive patches.
Affected products
- Seres Software syWEB through 27082026
Timeline
- 2026-08-27: disclosed
- other: Vendor confirmed product is no longer supported and will not receive patches