CWE-613
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
531 vulnerabilities with CWE-613
CVE-2026-44188
MEDIUM
Ansible-lightspeed: ansible lightspeed: session hijacking and unauthorized data access due to insufficient session expiration
CVSS 5.3
CVE-2026-53830
MEDIUM
OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload
CVSS 6.5
CVE-2026-53824
MEDIUM
Mattermost < 2026.4.24 - Slash Token Revocation Lag via Monitor Refresh Delay
CVSS 6.5
CVE-2026-46657
HIGH
Bludit's persistent authentication tokens not revoked upon account disablement
CVSS 7.1
CVE-2026-46656
HIGH
Bludit CMS has improper authorization and mediation failure leading to persistent ghost sessions
CVSS 8.8
CVE-2026-46401
MEDIUM
haxtheweb issues - HAX CMS PHP Has Insufficient Session Expiration
CVE-2026-48726
MEDIUM
Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path
CVSS 6.5
CVE-2026-44648
HIGH
SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
CVSS 7.5
CVE-2026-9802
MEDIUM
Keycloak: keycloak: unauthorized account access via replayed refresh tokens after cluster restart
CVSS 6.8
CVE-2026-8670
CRITICAL
syslink software Avantra - Insecure Session Handling on Metrics Web Server
CVSS 9.6
CVE-2026-1815
MEDIUM
Session Hijacking in TEİAŞ's Mobile Application
CVSS 5.7
CVE-2026-44553
HIGH
Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
CVSS 8.1
CVE-2026-22706
MEDIUM
Strapi: Password Reset Does Not Revoke Existing Refresh Sessions
CVSS 6.5
CVE-2026-44511
HIGH
Katalyst Koi: Session cookies can be replayed after user logout
CVSS 7.4
CVE-2026-5545
MEDIUM
curl 8.7.0-8.19.0 - Insufficient Session Expiration via Connection Reuse
CVSS 6.5
CVE-2026-44873
MEDIUM
Insufficient Session Invalidation on User Account Deactivation in AOS-8 Operating System
CVSS 5.4
CVE-2026-43983
HIGH
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
CVSS 8.1
CVE-2026-43911
MEDIUM
Vaultwarden: Refresh tokens not invalidated on security stamp rotation
CVSS 6.8
CVE-2026-41902
CRITICAL
FreeScout's user invitation hash never expires: permanent unauthenticated account takeover if invite link leaks
CVSS 9.1
CVE-2026-41519
MEDIUM
Weblate's API Token Not Invalidated on Password Change
CVSS 4.2
CVE-2026-41891
MEDIUM
CI4MS: Deactivated User Session Bypass (active=0)
CVE-2026-40934
MEDIUM
jupyter-server authentication cookies remain valid after password reset due to static cookie secret
CVSS 6.8
CVE-2026-42421
MEDIUM
OpenClaw < 2026.4.8 - WebSocket Session Persistence via Shared Gateway Token Rotation
CVSS 5.4
CVE-2026-41916
MEDIUM
OpenClaw < 2026.4.8 - Stale Authentication State via Config Reload
CVSS 5.4
CVE-2026-25720
MEDIUM
SenseLive X3050 Insufficient session expiration
CVSS 5.4
Details
Vulnerabilities
531