Junglewise Threat Intelligence

CVE-2026-88262: Bizwell xClick insufficient session expiration authentication bypass

CVE-2026-88262 · Severity: info · CVSS 0 · Published 2026-09-15

Executive brief

Bizwell xClick is an enterprise groupware platform that handles email, approvals, scheduling, and document management for corporate teams. An insufficient session expiration vulnerability allows attackers to reuse or hijack user sessions to bypass authentication and gain unauthorized access to business-critical functions and data.

Technical details

The vulnerability stems from insufficient session expiration controls in xClick, allowing sessions to persist longer than intended or be reused after a user logs out. An attacker with access to an active or abandoned session token could bypass authentication mechanisms and perform actions as the compromised user. This may require physical access to an unlocked workstation, network sniffing, or exploitation of session storage on shared systems. The exact attack preconditions and available patches are not specified in the advisory.

Affected products

  • Bizwell xClick R2, R3, R3.1

Timeline

  • 2026-09-15: disclosed

References

Related threats