---
id: CVE-2026-92419
title: >-
  WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the
  /api/vacations/{path} endpoint
summary: >-
  WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the
  /api/vacations/{path} endpoint. The selectedPeople parameter in the Gantt
  vacation chart API does not validate whether the requesting user is authorized
  to access…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-639
vendor: WEBCON
product: WEBCON BPS
affected:
  - bps >= 2024.1.1.145 < 2025.2.1.177
  - bps >= 2026.1.1.1 < 2026.1.1.20
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T16:16:47.660'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92419'
references:
  - url: 'https://cert.pl/en/posts/2026/09/CVE-2026-92419'
    label: cvd@cert.pl
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-23T15:20:04.450494Z'
cvssSource: cna
ingestedAt: '2026-09-23T15:26:23.423Z'
epss: 0.0031
epssPercentile: 0.21151
---

## Overview

WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the /api/vacations/{path} endpoint. The selectedPeople parameter in the Gantt vacation chart API does not validate whether the requesting user is authorized to access the requested users' data. An authenticated attacker can supply arbitrary user logins in the selectedPeople parameter to view vacation schedules of other employees, including managers and staff from other offices, regardless of business logic access restrictions, resulting in unauthorized disclosure of sensitive scheduling information.This vulnerability was fixed in versions: 2025.2.1.177 and 2026.1.1.20

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
