CWE-613

Insufficient Session Expiration

Parent: CWE-672 - Operation on a Resource after Expiration or Release

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

531 vulnerabilities with CWE-613
CVE-2026-27764 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
CVE-2026-20748 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
CVE-2026-24912 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
CVE-2026-21622 CRITICAL
hexpm - Insufficient Session Expiration in Password Reset Token
CVSS 9.8
CVE-2026-28396 MEDIUM
NocoDB < 0.301.3 - Insufficient Session Expiration via Password Reset Flow
CVSS 6.5
CVE-2026-3401 LOW
SourceCodester Pharmacy Mgmt 1.0 - Auth Bypass
CVSS 3.1
CVE-2026-27647 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
CVE-2026-26290 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
CVE-2026-27652 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
CVE-2026-25778 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
CVE-2026-25711 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
CVE-2026-20895 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
CVE-2026-28275 HIGH
Initiative < 0.32.4 - Insufficient Session Expiration via JWT Token Invalidation
CVSS 8.1
CVE-2026-27968 MEDIUM
packistry < 0.13.0 - Improper Authentication via Expired Deploy Token
CVSS 4.3
CVE-2026-27933 MEDIUM
Manyfold < 0.133.0 - Session Hijack via Proxy Cache Cookie Leakage
CVSS 6.8
CVE-2026-27575 CRITICAL
Vikunja < 2.0.0 - Insufficient Session Expiration and Weak Password Enforcement
CVSS 9.1
CVE-2026-25476 HIGH
OpenEMR < 8.0.0 - Insufficient Session Expiration via skip_timeout_reset Parameter
CVSS 7.5
CVE-2026-26342 CRITICAL
Tattile Smart+/Vega/Basic <1.181.5 - Auth Bypass
CVSS 9.8
CVE-2026-1842 MEDIUM
HyperCloud 2.3.5-2.6.8 - Auth Bypass
CVE-2026-1435 CRITICAL
Graylog Web Interface 2.2.3 - Auth Bypass
CVSS 9.8
CVE-2026-24894 HIGH
FrankenPHP <1.11.2 - Info Disclosure
CVSS 7.5
CVE-2026-24669 HIGH
Open eClass <4.2 - Privilege Escalation
CVSS 7.8
CVE-2026-24667 MEDIUM
Open eClass Platform < 4.2 - Insufficient Session Expiration after Password Change
CVSS 5.0
CVE-2026-24472 MEDIUM
Hono < 4.11.7 - Information Disclosure via Cache Middleware
CVSS 5.3
CVE-2025-12624 MEDIUM
Improper Token Invalidation in WSO2 Identity Server Allows Access After Account Lock
CVSS 6.0
Details
Vulnerabilities 531