CWE-613

Insufficient Session Expiration

Parent: CWE-672 - Operation on a Resource after Expiration or Release

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

531 vulnerabilities with CWE-613
CVE-2026-44188 MEDIUM
Ansible-lightspeed: ansible lightspeed: session hijacking and unauthorized data access due to insufficient session expiration
CVSS 5.3
CVE-2026-53830 MEDIUM
OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload
CVSS 6.5
CVE-2026-53824 MEDIUM
Mattermost < 2026.4.24 - Slash Token Revocation Lag via Monitor Refresh Delay
CVSS 6.5
CVE-2026-46657 HIGH
Bludit's persistent authentication tokens not revoked upon account disablement
CVSS 7.1
CVE-2026-46656 HIGH
Bludit CMS has improper authorization and mediation failure leading to persistent ghost sessions
CVSS 8.8
CVE-2026-46401 MEDIUM
haxtheweb issues - HAX CMS PHP Has Insufficient Session Expiration
CVE-2026-48726 MEDIUM
Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path
CVSS 6.5
CVE-2026-44648 HIGH
SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
CVSS 7.5
CVE-2026-9802 MEDIUM
Keycloak: keycloak: unauthorized account access via replayed refresh tokens after cluster restart
CVSS 6.8
CVE-2026-8670 CRITICAL
syslink software Avantra - Insecure Session Handling on Metrics Web Server
CVSS 9.6
CVE-2026-1815 MEDIUM
Session Hijacking in TEİAŞ's Mobile Application
CVSS 5.7
CVE-2026-44553 HIGH
Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
CVSS 8.1
CVE-2026-22706 MEDIUM
Strapi: Password Reset Does Not Revoke Existing Refresh Sessions
CVSS 6.5
CVE-2026-44511 HIGH
Katalyst Koi: Session cookies can be replayed after user logout
CVSS 7.4
CVE-2026-5545 MEDIUM
curl 8.7.0-8.19.0 - Insufficient Session Expiration via Connection Reuse
CVSS 6.5
CVE-2026-44873 MEDIUM
Insufficient Session Invalidation on User Account Deactivation in AOS-8 Operating System
CVSS 5.4
CVE-2026-43983 HIGH
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
CVSS 8.1
CVE-2026-43911 MEDIUM
Vaultwarden: Refresh tokens not invalidated on security stamp rotation
CVSS 6.8
CVE-2026-41902 CRITICAL
FreeScout's user invitation hash never expires: permanent unauthenticated account takeover if invite link leaks
CVSS 9.1
CVE-2026-41519 MEDIUM
Weblate's API Token Not Invalidated on Password Change
CVSS 4.2
CVE-2026-41891 MEDIUM
CI4MS: Deactivated User Session Bypass (active=0)
CVE-2026-40934 MEDIUM
jupyter-server authentication cookies remain valid after password reset due to static cookie secret
CVSS 6.8
CVE-2026-42421 MEDIUM
OpenClaw < 2026.4.8 - WebSocket Session Persistence via Shared Gateway Token Rotation
CVSS 5.4
CVE-2026-41916 MEDIUM
OpenClaw < 2026.4.8 - Stale Authentication State via Config Reload
CVSS 5.4
CVE-2026-25720 MEDIUM
SenseLive X3050 Insufficient session expiration
CVSS 5.4
Details
Vulnerabilities 531