CVE-2026-1630: Reflected XSS in WEBCON BPS
WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can send a specially crafted URL that, when opened by an authenticated user, results in arbitrary JavaScript execution in the victim's browser.
This issue was fixed in versions 2026.1.3.109 and 2025.2.1.293.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WEBCON BPSto a version that resolves this vulnerability.Fixed in 2026.1.3.109 - Upgrade
Upgrade
WEBCON BPSto a version that resolves this vulnerability.Fixed in 2025.2.1.293
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1630?
CVE-2026-1630 has a medium severity rating due to its potential to allow reflected XSS attacks.
How do I fix CVE-2026-1630?
To fix CVE-2026-1630, update WEBCON BPS to version 2026.1.3.110 or later.
What systems are affected by CVE-2026-1630?
CVE-2026-1630 affects WEBCON BPS versions prior to 2026.1.3.110 and 2025.2.1.294.
What type of attack does CVE-2026-1630 enable?
CVE-2026-1630 enables reflected XSS attacks through crafted URLs sent to authenticated users.
What are the consequences of CVE-2026-1630?
The consequences of CVE-2026-1630 include potential unauthorized JavaScript execution in the victim's browser.