Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Robert Strzoda

#51688of 57,427
5.3Total CVSS
Vulnerabilities · 1
PT-2026-97344
5.3
2026-09-23
Unknown · Webcon Bps · CVE-2026-92419
**Name of the Vulnerable Software and Affected Versions** WEBCON BPS versions prior to 2025.2.1.177 WEBCON BPS versions prior to 2026.1.1.20 **Description** An Insecure Direct Object Reference (IDOR) exists in the '/api/vacations/{path}' endpoint. The Gantt vacation chart API fails to validate if the requesting user is authorized to access data for the users specified in the `selectedPeople` parameter. An authenticated attacker can provide arbitrary user logins in the `selectedPeople` parameter to view the vacation schedules of other employees, including managers and staff from different offices, bypassing business logic access restrictions and leading to the unauthorized disclosure of sensitive scheduling information. **Recommendations** Update to version 2025.2.1.177. Update to version 2026.1.1.20. As a temporary mitigation, restrict access to the '/api/vacations/{path}' endpoint or avoid using the `selectedPeople` parameter until the updates are applied.