# WEBCON BPS Patches Reflected XSS Flaw

Published: 2026-05-14 · Severity: low
Canonical: https://vorant.io/reports/75cc2ffb-633d-50dc-bc7e-a0cc2943e6c0/webcon-bps-patches-reflected-xss-flaw

> A reflected XSS vulnerability in WEBCON BPS's /openinmobileapp endpoint could let attackers run JavaScript in authenticated users' browsers via crafted URLs.

CERT Polska coordinated the disclosure of CVE-2026-1630, a reflected cross-site scripting vulnerability in WEBCON BPS, a business process management platform. The flaw resides in a parameter handled by the /openinmobileapp endpoint, allowing an attacker to craft a malicious URL that, when clicked by an authenticated user, executes arbitrary JavaScript in the victim's browser context.

The vulnerability was responsibly disclosed by researcher Konrad Szczepaniak and has been fixed by the vendor in versions 2026.1.3.109 and 2025.2.1.293. There is no indication of active exploitation in the wild; this is a standard coordinated disclosure advisory. Organizations running affected WEBCON BPS versions should update to the patched releases to prevent session hijacking, credential theft, or other client-side attacks stemming from reflected XSS.

## Mentioned in this report

- Vulnerabilities: CVE-2026-1630

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-1630

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/75cc2ffb-633d-50dc-bc7e-a0cc2943e6c0/webcon-bps-patches-reflected-xss-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
