CVE-2026-88262
moderateInsufficient Session Expiration Enables Authentication Bypass in bizwell xClick R2–R3.1
bizwell xClick versions R2, R3, and R3.1 contain an insufficient session expiration flaw (CWE-613) that permits authentication bypass. Because the product fails to properly invalidate session credentials when they should expire — for example after logout or an idle timeout — an attacker who obtains a previously issued session token (from a compromised device, a logged-out browser, or an intercepted cookie) can replay it to regain authenticated access without valid login credentials. Successful exploitation bypasses authentication and grants the attacker the legitimate user's privileges, with high impact on the confidentiality, integrity, and availability of the affected site (CVSS v4.0: 8.7, network-exploitable with no privileges required). The vendor's customer base — typically Japanese public-sector bodies, schools, and enterprises running xClick-built websites on R2, R3, or R3.1 — is affected. No public proof-of-concept exists, no exploitation in the wild has been reported, and the issue is not on the CISA Known Exploited Vulnerabilities list.
What to do: Contact bizwell support and deploy a fixed release as soon as one is available, since R2, R3, and R3.1 are all listed as affected and no patched version is named in the advisory. In the meantime, shorten session lifetimes, force all users to re-authenticate to invalidate existing sessions, and enforce Secure/HttpOnly cookies served only over HTTPS. Review web and application logs for session tokens being reused after logout or from unfamiliar IP addresses or locations.
| bizwell xClick | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1.
- Weakness
- CWE-613
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.