CVE-2026-88262

8.7

BizWell · xClick

BizWell xClick contains an insufficient session expiration flaw that allows unauthorized parties to bypass authentication by reusing old session tokens.

Executive summary

A critical authentication bypass vulnerability in BizWell xClick versions R2, R3, and R3.1 enables attackers to hijack user sessions via insufficient session expiration mechanisms.

Vulnerability

This vulnerability involves insufficient session expiration, which allows an attacker to reuse previously captured or expired session tokens to regain access to protected system resources. The flaw permits unauthenticated attackers to bypass standard login requirements.

Business impact

The ability to bypass authentication mechanisms creates a high risk of unauthorized access to confidential groupware data and system functionalities. This vulnerability, rated at 8.7 on the CVSS scale, could lead to significant data exposure or unauthorized administrative actions within the xClick environment.

Remediation

Immediate Action: Apply all available security updates provided by BizWell for the xClick platform immediately.

Proactive Monitoring: Review system access logs for anomalies, such as multiple successful logins using tokens that should have expired or irregular session patterns.

Compensating Controls: Implement strict network access controls and session timeouts at the application gateway level to limit the window of opportunity for token reuse.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Administrators should consult the official BizWell advisory for the latest patches. Until a patch is applied, ensure that access to the xClick application is restricted to trusted networks to minimize the risk of unauthorized session reuse.

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Analyst report updated
  5. Published in the daily brief high section

Sources

Originally found and disclosed by Hyunho, Cho (조현호), per the CVE Program record.