ZeroHour

CVE-2026-88262

moderate

Insufficient Session Expiration Enables Authentication Bypass in bizwell xClick R2–R3.1

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

bizwell xClick versions R2, R3, and R3.1 contain an insufficient session expiration flaw (CWE-613) that permits authentication bypass. Because the product fails to properly invalidate session credentials when they should expire — for example after logout or an idle timeout — an attacker who obtains a previously issued session token (from a compromised device, a logged-out browser, or an intercepted cookie) can replay it to regain authenticated access without valid login credentials. Successful exploitation bypasses authentication and grants the attacker the legitimate user's privileges, with high impact on the confidentiality, integrity, and availability of the affected site (CVSS v4.0: 8.7, network-exploitable with no privileges required). The vendor's customer base — typically Japanese public-sector bodies, schools, and enterprises running xClick-built websites on R2, R3, or R3.1 — is affected. No public proof-of-concept exists, no exploitation in the wild has been reported, and the issue is not on the CISA Known Exploited Vulnerabilities list.

What to do: Contact bizwell support and deploy a fixed release as soon as one is available, since R2, R3, and R3.1 are all listed as affected and no patched version is named in the advisory. In the meantime, shorten session lifetimes, force all users to re-authenticate to invalidate existing sessions, and enforce Secure/HttpOnly cookies served only over HTTPS. Review web and application logs for session tokens being reused after logout or from unfamiliar IP addresses or locations.

Affected
bizwell xClick
Estimated exposure
moderate≈ low thousands of websites (order-of-magnitude estimate; xClick is a proprietary CMS widely adopted by Japanese local governments, schools, and enterprises,… — Estimated from xClick's known deployment pattern among Japanese public-sector and enterprise websites; no active-install statistics or internet-wide scan data are available for this commercial CMS, so the figure is a clearly approximate,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1.

Weakness
CWE-613
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.