Description
Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass.

This issue affects xClick: R2, R3, and R3.1.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

An insufficient session expiration flaw in bizwell xClick permits an attacker to bypass authentication controls, enabling unauthorized access to protected resources or data. The vulnerability allows session tokens to remain valid beyond the intended period, creating a window for attack. The impact is an authentication bypass, giving the attacker unauthorized privilege.

Affected Systems

The flaw affects bizwell xClick releases R2, R3, and R3.1. All installations of these versions are susceptible unless mitigated by a vendor update or configuration change.

Risk and Exploitability

The CVSS score of 8.7 reflects high severity, and an EPSS score of under 1% indicates a low but non‑zero likelihood of exploitation. Because the vulnerability is not listed in CISA's KEV catalog, no prioritized exploit data is currently available. Attackers could exploit the flaw remotely via the web interface by reusing stale session tokens, so environments with insufficient session invalidation are at greatest risk.

Generated by OpenCVE AI on September 17, 2026 at 18:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor patch that enforces strict session expiration
  • Configure the application to invalidate sessions immediately after user logout or after a short idle period
  • Ensure session identifiers are regenerated upon each successful authentication to prevent session fixation

Generated by OpenCVE AI on September 17, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Insufficient Session Expiration Enables Authentication Bypass in bizwell xClick

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Bizwell
Bizwell xclick
Vendors & Products Bizwell
Bizwell xclick

Wed, 16 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass due to Insufficient Session Expiration

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass due to Insufficient Session Expiration

Tue, 15 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1.
Weaknesses CWE-613
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: FSI

Published:

Updated: 2026-09-15T18:11:16.328Z

Reserved: 2026-09-10T00:47:25.131Z

Link: CVE-2026-88262

cve-icon Vulnrichment

Updated: 2026-09-15T18:11:12.408Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T03:17:06.233

Modified: 2026-09-18T19:41:42.593

Link: CVE-2026-88262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration