CVE-2026-88262: Bizwell Xclick
High severity, CVSS 8.7. EPSS: 0.6% chance of exploitation in the next 30 days.
Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1.
Affected products
- Bizwell Xclick: version R2 only; version R3 only; version R3.1 only
Published 2026-09-15. Last modified 2026-09-18.