CWE-613
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
575 vulnerabilities with CWE-613
CVE-2026-54479
HIGH
EVoke Systems EVoke CSMS Insufficient Session Expiration
CVSS 7.3
CVE-2026-9705
MEDIUM
Keycloak: keycloak: attacker can re-enable and take over disabled clients via registration access token
CVSS 6.5
CVE-2026-52809
MEDIUM
Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
CVSS 6.8
CVE-2026-49277
LOW
Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation
CVE-2026-45757
LOW
Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens
CVE-2026-53928
MEDIUM
NocoDB: Refresh Tokens Persist Through Password Recovery
CVE-2026-53926
MEDIUM
NocoDB: OAuth Tokens Persist Through Security Events
CVE-2026-46554
LOW
NocoDB: Stale Auth Cache After API Token Deletion
CVE-2026-54321
HIGH
Daytona: Public sandbox previews remain accessible for up to one hour after being made private
CVSS 7.0
CVE-2026-55423
MEDIUM
Langflow: Logout button does not clear session
CVSS 6.1
CVE-2026-9162
MEDIUM
Global session revocation does not invalidate active WebSocket connections
CVSS 4.3
CVE-2026-12796
MEDIUM
BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration
CVSS 6.3
CVE-2026-12772
MEDIUM
BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expiration
CVSS 6.3
CVE-2026-53843
HIGH
OpenClaw < 2026.5.26 - Node Token Revocation Bypass via Pairing-Scoped Device Session
CVSS 8.8
CVE-2026-53776
CRITICAL
Perry < 0.5.1166 JWT Expiration Bypass via verify_decode
CVSS 9.1
CVE-2026-44188
MEDIUM
Ansible-lightspeed: ansible lightspeed: session hijacking and unauthorized data access due to insufficient session expiration
CVSS 5.3
CVE-2026-53830
MEDIUM
OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload
CVSS 6.5
CVE-2026-53824
MEDIUM
Mattermost < 2026.4.24 - Slash Token Revocation Lag via Monitor Refresh Delay
CVSS 6.5
CVE-2026-46657
HIGH
Bludit's persistent authentication tokens not revoked upon account disablement
CVSS 7.1
CVE-2026-46656
HIGH
Bludit CMS has improper authorization and mediation failure leading to persistent ghost sessions
CVSS 8.8
CVE-2026-46401
MEDIUM
haxtheweb issues - HAX CMS PHP Has Insufficient Session Expiration
CVE-2026-48726
MEDIUM
Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path
CVSS 6.5
CVE-2026-44648
HIGH
SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
CVSS 7.5
CVE-2026-9802
MEDIUM
Keycloak: keycloak: unauthorized account access via replayed refresh tokens after cluster restart
CVSS 6.8
CVE-2026-8670
CRITICAL
syslink software Avantra - Insecure Session Handling on Metrics Web Server
CVSS 9.6
Details
Vulnerabilities
575