CWE-613
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
575 vulnerabilities with CWE-613
CVE-2026-14227
MEDIUM
Insufficient session expiration in MikroTik RouterOS
CVSS 4.9
CVE-2026-16970
MEDIUM
DFIR-IRIS Insufficient Logout Implementation
CVSS 4.2
CVE-2026-66400
MEDIUM
Grav Login Plugin before 3.8.13 Insufficient Session Expiration
CVSS 4.8
CVE-2026-14996
HIGH
IBM Aspera Faspex 5 5.0.0-5.0.15.4 - Insufficient Session Expiration
CVSS 8.2
CVE-2026-15967
HIGH
MOVEit Transfer refresh-token processing does not enforce updated account restrictions
CVSS 7.5
CVE-2026-64829
HIGH
Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow
CVSS 7.4
CVE-2026-56583
LOW
HCL MyCloud was affected with Concurrent Login Vulnerability.
CVSS 3.1
CVE-2026-63753
MEDIUM
SurrealDB before 3.1.0 Authentication Bypass via LIVE Query
CVSS 4.3
CVE-2026-16206
MEDIUM
django-oauth django-oauth-toolkit oauth2_validators.py _load_id_token session expiration
CVSS 6.3
CVE-2026-63089
CRITICAL
WireGuard Easy Weak Token Generation Information Disclosure via OTL Route
CVSS 9.3
CVE-2026-63175
HIGH
Cross-Capture Session Data Leakage Due to Shared Mutable State in Looklyloo - PlaywrightCapture
CVE-2026-61452
MEDIUM
Grav before 2.0.4 Improper Session Invalidation JWT Access Tokens
CVSS 5.3
CVE-2026-56400
HIGH
open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation
CVSS 8.3
CVE-2026-48329
LOW
Adobe ColdFusion 2025 - ColdFusion | Insufficient Session Expiration (CWE-613)
CVSS 2.7
CVE-2026-44383
HIGH
Hydro-Québec Le Circuit Electrique charging station backend Insufficient Session Expiration
CVSS 7.5
CVE-2026-56665
MEDIUM
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
CVSS 4.2
CVE-2026-56664
MEDIUM
ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
CVSS 4.2
CVE-2026-28564
CRITICAL
Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
CVSS 9.8
CVE-2026-59219
HIGH
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
CVSS 7.1
CVE-2026-54779
MEDIUM
CoreWCF: SAML token replay protection is inoperative
CVSS 5.9
CVE-2026-49229
HIGH
Actual: Disabled OpenID users keep access through existing session tokens
CVSS 8.3
CVE-2026-42172
LOW
Coolify: Sanctum API Tokens Have No Expiration — Leaked Tokens Grant Permanent Access
CVSS 3.1
CVE-2026-43918
HIGH
FOSSBilling < 0.8.0 - Suspended Account Session Retention
CVE-2026-46455
CRITICAL
Apache Camel Keycloak - Expired Token Acceptance
CVSS 9.8
CVE-2026-14725
MEDIUM
SourceCodester Online Boat Reservation System session expiration
CVSS 6.3
Details
Vulnerabilities
575