| CVE ID | CVE-2026-1630 |
| Publication date | 14 May 2026 |
| Vendor | WEBCON |
| Product | WEBCON BPS |
| Vulnerable versions | From 2026.1.1.45 below 2026.1.3.109 From 2025.1.1.87 before 2025.2.1.293 |
| Vulnerability type (CWE) | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') (CWE-79) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in WEBCON BPS software and participated in coordination of its disclosure.
The vulnerability CVE-2026-1630: WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by /openinmobileapp endpoint. An attacker can send a specially crafted URL that, when opened by an authenticated user, results in arbitrary JavaScript execution in the victim's browser.
This issue was fixed in versions 2026.1.3.109 and 2025.2.1.293.
Credits
We thank Konrad Szczepaniak for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.