CVE-2026-88262: Bizwell/xClick vulnerability
Published Sep 15, 2026
·Updated
Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass.
This issue affects xClick: R2, R3, and R3.1.
Affected Software
1 affected component
bizwell/xClick>=R2<=R3.1
Event History
Sep 15, 2026
CVE Published
via MITRE·02:16 AM
Data Sourced
via MITRE·02:16 AM
DescriptionWeakness
Frequently Asked Questions
1
Which xClick releases are affected?
The affected releases are xClick R2, R3, and R3.1.
2
What weakness enables the authentication bypass?
The issue is insufficient session expiration, which can allow authentication bypass.