VORANT. Threat Intelligence Sign in Get the full feed

WEBCON BPS IDOR exposes employee vacation data

routine vulnerability technology

An IDOR flaw in WEBCON BPS lets authenticated users view other employees' vacation schedules; patched in 2025.2.1.177 and 2026.1.1.20.

CERT Polska coordinated disclosure of CVE-2026-92419, an Insecure Direct Object Reference vulnerability in WEBCON BPS's /api/vacations/{path} endpoint. The selectedPeople parameter in the Gantt vacation chart API fails to verify whether the requesting user is authorized to view the data of the specified users. Any authenticated attacker can supply arbitrary user logins in this parameter to retrieve vacation schedules for other staff, including managers and employees at other offices, bypassing intended business-logic access restrictions.

The impact is limited to unauthorized disclosure of sensitive scheduling information rather than remote code execution or system compromise, but it could aid social engineering, reconnaissance, or privacy violations within an organization. There is no indication of active exploitation in the wild; this was a responsibly reported vulnerability coordinated through CERT Polska's CVD process, credited to researcher Robert Strzoda.

Defenders running WEBCON BPS should upgrade to the fixed versions 2025.2.1.177 or 2026.1.1.20 as soon as possible. Organizations unable to patch immediately should monitor API access logs for the /api/vacations/{path} endpoint for requests specifying selectedPeople values corresponding to users outside the requester's normal scope or reporting chain, which may indicate probing or abuse of this IDOR.

Mentioned in this report

Vulnerabilities CVE-2026-92419

Source reporting: https://cert.pl/en/posts/2026/09/CVE-2026-92419

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free