# WEBCON BPS software contains a reflected XSS vulnerability (CVE-2026-1630) in the…

Published: 2026-05-14 · Severity: medium
Canonical: https://vorant.io/reports/3c9d811b-83c5-4ce5-950e-a5c87c6dbd93/webcon-bps-software-contains-a-reflected-xss-vulnerability-cve-2026-1630-in-the

> WEBCON BPS software contains a reflected XSS vulnerability (CVE-2026-1630) in the /openinmobileapp endpoint that allows JavaScript execution in authenticated users' browsers.

CERT Polska coordinated the disclosure of CVE-2026-1630, a reflected cross-site scripting vulnerability in WEBCON BPS software. The vulnerability exists in a parameter used by the /openinmobileapp endpoint. An attacker can exploit this flaw by sending a specially crafted URL to an authenticated user. When the victim opens the malicious link, arbitrary JavaScript code executes in their browser session, potentially allowing session hijacking, credential theft, or other malicious actions within the context of the authenticated WEBCON BPS session.

The vulnerability was responsibly reported by security researcher Konrad Szczepaniak and has been patched by the vendor. Organizations running WEBCON BPS should upgrade to version 2026.1.3.109 or 2025.2.1.293 to remediate this issue. The vulnerability requires user interaction (clicking a malicious link) but targets authenticated users, making it a viable attack vector in phishing or social engineering campaigns targeting WEBCON BPS deployments.

## Mentioned in this report

- Vulnerabilities: CVE-2026-1630

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-1630

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3c9d811b-83c5-4ce5-950e-a5c87c6dbd93/webcon-bps-software-contains-a-reflected-xss-vulnerability-cve-2026-1630-in-the.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
