CVE-2026-1630 Details
Description
WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can send a specially crafted URL that, when opened by an authenticated user, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed in versions 2026.1.3.109 and 2025.2.1.293.
A reflected cross-site scripting vulnerability has been identified in WEBCON BPS. This issue affects versions 2026.1.1.45 prior to 2026.1.3.109 and versions 2025.1.1.87 prior to 2025.2.1.293. The vulnerability arises in the '/openinmobileapp' endpoint, where an attacker can send a specially crafted URL. When this URL is opened by an authenticated user, it allows for the execution of arbitrary JavaScript in the user's browser.
Users can upgrade to WEBCON BPS versions 2026.1.3.109 or 2025.2.1.293 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 14, 2026CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/en/posts/2026/05/CVE-2026-1630/ | [email protected] | AdvisoryRemedy |
| https://community.webcon.com/download/changelog/394?q=6a8b113 | [email protected] | Release NotesVendor |
| https://community.webcon.com/download/changelog/398?q=db746ec | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WEBCON BPS | >= 2026.1.1.45, < 2026.1.3.109 >= 2025.1.1.87, < 2025.2.1.293 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | New CVE Received | [email protected] |
Volerion