CVE-2026-92419 Details
Description
WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the /api/vacations/{path} endpoint. The selectedPeople parameter in the Gantt vacation chart API does not validate whether the requesting user is authorized to access the requested users' data. An authenticated attacker can supply arbitrary user logins in the selectedPeople parameter to view vacation schedules of other employees, including managers and staff from other offices, regardless of business logic access restrictions, resulting in unauthorized disclosure of sensitive scheduling information.This vulnerability was fixed in versions: 2025.2.1.177 and 2026.1.1.20
A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in WEBCON BPS within the Gantt vacation chart API, specifically at the '/api/vacations/{path}' endpoint. The issue arises because the 'selectedPeople' parameter does not properly validate user authorization for accessing the data of other users. This flaw enables authenticated attackers to manipulate the 'selectedPeople' parameter with arbitrary user logins, thereby gaining unauthorized access to the vacation schedules of other employees, including managers and staff from different offices. This exploitation occurs regardless of existing business logic access controls, leading to an unauthorized disclosure of sensitive scheduling information. The vulnerability affects WEBCON BPS versions 2024.1.1.145 prior to 2025.2.1.177 and versions 2026.1.1.1 prior to 2026.1.1.20.
Users can upgrade to WEBCON BPS versions 2025.2.1.177 or 2026.1.1.20 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 23, 2026CISA-ADP
Assessed Sep 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/en/posts/2026/09/CVE-2026-92419 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WEBCON BPS | >= 2024.1.1.145, < 2025.2.1.177 >= 2026.1.1.1, < 2026.1.1.20 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2026 | New CVE Received | [email protected] |
Volerion