CVE-2026-88262: Bizwell Xclick

High severity, CVSS 8.7. EPSS: 0.6% chance of exploitation in the next 30 days.

Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1.

Affected products

  • Bizwell Xclick: version R2 only; version R3 only; version R3.1 only

Published 2026-09-15. Last modified 2026-09-18.