CWE-613

Insufficient Session Expiration

Parent: CWE-672 - Operation on a Resource after Expiration or Release

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

575 vulnerabilities with CWE-613
CVE-2026-14227 MEDIUM
Insufficient session expiration in MikroTik RouterOS
CVSS 4.9
CVE-2026-16970 MEDIUM
DFIR-IRIS Insufficient Logout Implementation
CVSS 4.2
CVE-2026-66400 MEDIUM
Grav Login Plugin before 3.8.13 Insufficient Session Expiration
CVSS 4.8
CVE-2026-14996 HIGH
IBM Aspera Faspex 5 5.0.0-5.0.15.4 - Insufficient Session Expiration
CVSS 8.2
CVE-2026-15967 HIGH
MOVEit Transfer refresh-token processing does not enforce updated account restrictions
CVSS 7.5
CVE-2026-64829 HIGH
Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow
CVSS 7.4
CVE-2026-56583 LOW
HCL MyCloud was affected with Concurrent Login Vulnerability.
CVSS 3.1
CVE-2026-63753 MEDIUM
SurrealDB before 3.1.0 Authentication Bypass via LIVE Query
CVSS 4.3
CVE-2026-16206 MEDIUM
django-oauth django-oauth-toolkit oauth2_validators.py _load_id_token session expiration
CVSS 6.3
CVE-2026-63089 CRITICAL
WireGuard Easy Weak Token Generation Information Disclosure via OTL Route
CVSS 9.3
CVE-2026-63175 HIGH
Cross-Capture Session Data Leakage Due to Shared Mutable State in Looklyloo - PlaywrightCapture
CVE-2026-61452 MEDIUM
Grav before 2.0.4 Improper Session Invalidation JWT Access Tokens
CVSS 5.3
CVE-2026-56400 HIGH
open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation
CVSS 8.3
CVE-2026-48329 LOW
Adobe ColdFusion 2025 - ColdFusion | Insufficient Session Expiration (CWE-613)
CVSS 2.7
CVE-2026-44383 HIGH
Hydro-Québec Le Circuit Electrique charging station backend Insufficient Session Expiration
CVSS 7.5
CVE-2026-56665 MEDIUM
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
CVSS 4.2
CVE-2026-56664 MEDIUM
ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
CVSS 4.2
CVE-2026-28564 CRITICAL
Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
CVSS 9.8
CVE-2026-59219 HIGH
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
CVSS 7.1
CVE-2026-54779 MEDIUM
CoreWCF: SAML token replay protection is inoperative
CVSS 5.9
CVE-2026-49229 HIGH
Actual: Disabled OpenID users keep access through existing session tokens
CVSS 8.3
CVE-2026-42172 LOW
Coolify: Sanctum API Tokens Have No Expiration — Leaked Tokens Grant Permanent Access
CVSS 3.1
CVE-2026-43918 HIGH
FOSSBilling < 0.8.0 - Suspended Account Session Retention
CVE-2026-46455 CRITICAL
Apache Camel Keycloak - Expired Token Acceptance
CVSS 9.8
CVE-2026-14725 MEDIUM
SourceCodester Online Boat Reservation System session expiration
CVSS 6.3
Details
Vulnerabilities 575