Answer in brief
CVE-2026-1630 records a Unknown severity vulnerability in Reflected XSS in WEBCON BPS. The current sources do not mark it as known exploited. The current feed maps WEBCON/WEBCON BPS (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WEBCON/WEBCON BPS (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WEBCON/WEBCON BPSgeneric | >=2026.1.1.45 <2026.1.3.109 || >=2025.1.1.87 <2025.2.1.293 | 2026.1.3.109, 2025.2.1.293 |
Published upstream
May 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 24, 2026
WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can send a specially crafted URL that, when opened by an authenticated user, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed in versions 2026.1.3.109 and 2025.2.1.293.
Quoted source text, attributed separately from HOL analysis.