CVE-2026-92419 | WEBCON BPS prior 2025.2.1.177/2026.1.1.20 Gantt Vacation Chart API /api/vacations selectedPeople resource injection
A vulnerability categorized as problematic has been discovered in WEBCON BPS. Affected is an unknown function of the file /api/vacations of the component Gantt Vacation Chart API. The manipulation of the argument selectedPeople results in improper control of resource identifiers.
This vulnerability is known as CVE-2026-92419. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More