Unknown · Webcon Bps · CVE-2026-92419
**Name of the Vulnerable Software and Affected Versions**
WEBCON BPS versions prior to 2025.2.1.177
WEBCON BPS versions prior to 2026.1.1.20
**Description**
An Insecure Direct Object Reference (IDOR) exists in the '/api/vacations/{path}' endpoint. The Gantt vacation chart API fails to validate if the requesting user is authorized to access data for the users specified in the `selectedPeople` parameter. An authenticated attacker can provide arbitrary user logins in the `selectedPeople` parameter to view the vacation schedules of other employees, including managers and staff from different offices, bypassing business logic access restrictions and leading to the unauthorized disclosure of sensitive scheduling information.
**Recommendations**
Update to version 2025.2.1.177.
Update to version 2026.1.1.20.
As a temporary mitigation, restrict access to the '/api/vacations/{path}' endpoint or avoid using the `selectedPeople` parameter until the updates are applied.