PT-2026-97344 · Unknown · Webcon Bps

·

CVE-2026-92419

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions WEBCON BPS versions prior to 2025.2.1.177 WEBCON BPS versions prior to 2026.1.1.20
Description An Insecure Direct Object Reference (IDOR) exists in the '/api/vacations/{path}' endpoint. The Gantt vacation chart API fails to validate if the requesting user is authorized to access data for the users specified in the selectedPeople parameter. An authenticated attacker can provide arbitrary user logins in the selectedPeople parameter to view the vacation schedules of other employees, including managers and staff from different offices, bypassing business logic access restrictions and leading to the unauthorized disclosure of sensitive scheduling information.
Recommendations Update to version 2025.2.1.177. Update to version 2026.1.1.20. As a temporary mitigation, restrict access to the '/api/vacations/{path}' endpoint or avoid using the selectedPeople parameter until the updates are applied.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92419

Affected Products

Webcon Bps