CWE-613

Insufficient Session Expiration

Parent: CWE-672 - Operation on a Resource after Expiration or Release

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

575 vulnerabilities with CWE-613
CVE-2026-54479 HIGH
EVoke Systems EVoke CSMS Insufficient Session Expiration
CVSS 7.3
CVE-2026-9705 MEDIUM
Keycloak: keycloak: attacker can re-enable and take over disabled clients via registration access token
CVSS 6.5
CVE-2026-52809 MEDIUM
Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
CVSS 6.8
CVE-2026-49277 LOW
Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation
CVE-2026-45757 LOW
Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens
CVE-2026-53928 MEDIUM
NocoDB: Refresh Tokens Persist Through Password Recovery
CVE-2026-53926 MEDIUM
NocoDB: OAuth Tokens Persist Through Security Events
CVE-2026-46554 LOW
NocoDB: Stale Auth Cache After API Token Deletion
CVE-2026-54321 HIGH
Daytona: Public sandbox previews remain accessible for up to one hour after being made private
CVSS 7.0
CVE-2026-55423 MEDIUM
Langflow: Logout button does not clear session
CVSS 6.1
CVE-2026-9162 MEDIUM
Global session revocation does not invalidate active WebSocket connections
CVSS 4.3
CVE-2026-12796 MEDIUM
BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration
CVSS 6.3
CVE-2026-12772 MEDIUM
BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expiration
CVSS 6.3
CVE-2026-53843 HIGH
OpenClaw < 2026.5.26 - Node Token Revocation Bypass via Pairing-Scoped Device Session
CVSS 8.8
CVE-2026-53776 CRITICAL
Perry < 0.5.1166 JWT Expiration Bypass via verify_decode
CVSS 9.1
CVE-2026-44188 MEDIUM
Ansible-lightspeed: ansible lightspeed: session hijacking and unauthorized data access due to insufficient session expiration
CVSS 5.3
CVE-2026-53830 MEDIUM
OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload
CVSS 6.5
CVE-2026-53824 MEDIUM
Mattermost < 2026.4.24 - Slash Token Revocation Lag via Monitor Refresh Delay
CVSS 6.5
CVE-2026-46657 HIGH
Bludit's persistent authentication tokens not revoked upon account disablement
CVSS 7.1
CVE-2026-46656 HIGH
Bludit CMS has improper authorization and mediation failure leading to persistent ghost sessions
CVSS 8.8
CVE-2026-46401 MEDIUM
haxtheweb issues - HAX CMS PHP Has Insufficient Session Expiration
CVE-2026-48726 MEDIUM
Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path
CVSS 6.5
CVE-2026-44648 HIGH
SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
CVSS 7.5
CVE-2026-9802 MEDIUM
Keycloak: keycloak: unauthorized account access via replayed refresh tokens after cluster restart
CVSS 6.8
CVE-2026-8670 CRITICAL
syslink software Avantra - Insecure Session Handling on Metrics Web Server
CVSS 9.6
Details
Vulnerabilities 575