VORANT. Threat Intelligence Sign in Get the full feed

WEBCON BPS Patches Reflected XSS Flaw

low vulnerability

A reflected XSS vulnerability in WEBCON BPS's /openinmobileapp endpoint could let attackers run JavaScript in authenticated users' browsers via crafted URLs.

CERT Polska coordinated the disclosure of CVE-2026-1630, a reflected cross-site scripting vulnerability in WEBCON BPS, a business process management platform. The flaw resides in a parameter handled by the /openinmobileapp endpoint, allowing an attacker to craft a malicious URL that, when clicked by an authenticated user, executes arbitrary JavaScript in the victim's browser context.

The vulnerability was responsibly disclosed by researcher Konrad Szczepaniak and has been fixed by the vendor in versions 2026.1.3.109 and 2025.2.1.293. There is no indication of active exploitation in the wild; this is a standard coordinated disclosure advisory. Organizations running affected WEBCON BPS versions should update to the patched releases to prevent session hijacking, credential theft, or other client-side attacks stemming from reflected XSS.

Mentioned in this report

Vulnerabilities CVE-2026-1630

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-1630

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free