CWE-613

Insufficient Session Expiration

Parent: CWE-672 - Operation on a Resource after Expiration or Release

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

575 vulnerabilities with CWE-613
CVE-2026-1815 MEDIUM
Session Hijacking in TEİAŞ's Mobile Application
CVSS 5.7
CVE-2026-44553 HIGH
Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
CVSS 8.1
CVE-2026-22706 MEDIUM
Strapi: Password Reset Does Not Revoke Existing Refresh Sessions
CVSS 6.5
CVE-2026-44511 HIGH
Katalyst Koi: Session cookies can be replayed after user logout
CVSS 7.4
CVE-2026-5545 MEDIUM
curl 8.7.0-8.19.0 - Insufficient Session Expiration via Connection Reuse
CVSS 6.5
CVE-2026-44873 MEDIUM
Insufficient Session Invalidation on User Account Deactivation in AOS-8 Operating System
CVSS 5.4
CVE-2026-43983 HIGH
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
CVSS 8.1
CVE-2026-43911 MEDIUM
Vaultwarden: Refresh tokens not invalidated on security stamp rotation
CVSS 6.8
CVE-2026-41902 CRITICAL
FreeScout's user invitation hash never expires: permanent unauthenticated account takeover if invite link leaks
CVSS 9.1
CVE-2026-41519 MEDIUM
Weblate's API Token Not Invalidated on Password Change
CVSS 4.2
CVE-2026-41891 MEDIUM
CI4MS: Deactivated User Session Bypass (active=0)
CVE-2026-40934 MEDIUM
jupyter-server authentication cookies remain valid after password reset due to static cookie secret
CVSS 6.8
CVE-2026-42421 MEDIUM
OpenClaw < 2026.4.8 - WebSocket Session Persistence via Shared Gateway Token Rotation
CVSS 5.4
CVE-2026-41916 MEDIUM
OpenClaw < 2026.4.8 - Stale Authentication State via Config Reload
CVSS 5.4
CVE-2026-25720 MEDIUM
SenseLive X3050 Insufficient session expiration
CVSS 5.4
CVE-2026-41356 MEDIUM
OpenClaw < 2026.3.31 - Incomplete WebSocket Session Termination in device.token.rotate
CVSS 5.4
CVE-2026-1272 LOW
IBM Guardium Data Protection is affected by multiple vulnerabilities
CVSS 2.7
CVE-2026-6515 MEDIUM
Insufficient Session Expiration in GitLab
CVSS 5.4
CVE-2026-6848 MEDIUM
Quay: red hat quay: authentication bypass allows privileged actions without valid credentials
CVSS 5.4
CVE-2026-41133 HIGH
pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)
CVSS 8.8
CVE-2026-40939 MEDIUM
DSF: Missing Session Timeout for OIDC Sessions
CVE-2026-40587 MEDIUM
blueprintUE: Active Sessions Are Not Invalidated After Password Change or Reset
CVSS 6.5
CVE-2026-0971 MEDIUM
GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeout
CVSS 4.3
CVE-2026-34454 LOW
OAuth2 Proxy: Session cookie not cleared when rendering sign-in page
CVSS 3.5
CVE-2026-35594 MEDIUM
Vikunja Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
CVSS 6.5
Details
Vulnerabilities 575