CWE-613— Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."— MITRE CWE catalog
664 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-613page 4 of 14
- CVE-2026-20748HIGHCVSS 8.6EG 8.62026-03-06
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables s…
- CVE-2026-24912HIGHCVSS 8.6EG 8.62026-03-06
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables s…
- CVE-2025-65883HIGHCVSS 8.4EG 8.42025-12-04
A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local network attacker to achieve Remote Code Execution (RCE) with root privileges. The issue occurs due to improper session inva…
- CVE-2025-66223HIGHCVSS 8.4EG 8.42025-11-29
OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid even after the invited user is removed from the organization, and allow multiple invitati…
- CVE-2019-8803HIGHCVSS 8.4EG 8.42019-12-18
An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account of a previously log…
- CVE-2026-71206HIGHCVSS 8.3EG 8.32026-08-05
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocatio…
- CVE-2026-49229HIGHCVSS 8.3EG 8.32026-06-22
Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks future OpenID login for that identity, while existing Actual session tokens for the disabled user remain valid. The shar…
- CVE-2026-14996HIGHCVSS 8.2EG 8.22026-07-28
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.
- CVE-2025-42602HIGHCVSS 8.2EG 8.22025-04-23
This vulnerability exists in Meon KYC solutions due to improper handling of access and refresh tokens in certain API endpoints of authentication process. A remote attacker could exploit this vulnerability by intercepting and manipulating t…
- CVE-2023-5889HIGHCVSS 8.2EG 8.22023-11-01
Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
- CVE-2022-2820HIGHCVSS 7.0EG 8.22022-08-15
Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2.
- CVE-2026-103283HIGHCVSS 8.1EG 8.12026-10-01
Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff cr…
- CVE-2026-88805HIGHCVSS 8.1EG 8.12026-09-28
Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.
- CVE-2026-81268HIGHCVSS 8.1EG 8.12026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.
- CVE-2026-84203HIGHCVSS 8.1EG 8.12026-09-01
Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new acces…
- CVE-2025-71335HIGHCVSS 8.1EG 8.12026-06-25
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session tok…
- CVE-2026-44553HIGHCVSS 8.1EG 8.12026-05-15
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, administrative role changes and user deletions do not iterate SESSION_POOL to disconnect affected sessions. As a result, a u…
- CVE-2026-43983HIGHCVSS 8.1EG 8.12026-05-12
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) validates the refresh token's cryptographic integrity but does…
- CVE-2026-34503HIGHCVSS 8.1EG 8.12026-03-31
OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced reconne…
- CVE-2026-28275HIGHCVSS 8.1EG 8.12026-02-26
Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate previously issued JWT access tokens after a user changes their password. As a result, older tokens remain valid until ex…
- CVE-2025-53896HIGHCVSS 8.1EG 8.12025-11-29
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could cause under certain circumstances that a user's active session would not properly time out due to inactivity. This issue ha…
- CVE-2025-55278HIGHCVSS 8.1EG 8.12025-11-05
Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic signature. As a result, an attacker could potentia…
- CVE-2025-10223HIGHCVSS 8.1EG 8.12025-09-10
Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an une…
- CVE-2025-58437HIGHCVSS 8.1EG 8.12025-09-06
Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session handling in prebuilt workspaces. Coder automati…
- CVE-2021-47663HIGHCVSS 8.1EG 8.12025-04-24
Due to improper JSON Web Tokens implementation an unauthenticated remote attacker can guess a valid session ID and therefore impersonate a user to gain full access.
- CVE-2025-24896HIGHCVSS 8.1EG 8.12025-02-11
Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, a login token named `token` is stored in a cookie for authentication purposes in Bull Dashboard, but this remai…
- CVE-2024-45033HIGHCVSS 8.1EG 8.12025-01-08
Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with admin CLI, the sessions for that user have not been clea…
- CVE-2024-27782HIGHCVSS 8.1EG 8.12024-07-09
Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests.
- CVE-2023-33303HIGHCVSS 8.1EG 8.12023-10-13
A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api request
- CVE-2023-40537HIGHCVSS 8.1EG 8.12023-10-10
An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade VIPRION platform. Note: Software versions which have reached End of Technical Support (…
- CVE-2022-41672HIGHCVSS 8.1EG 8.12022-10-07
In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.
- CVE-2021-36330HIGHCVSS 8.1EG 8.12021-11-30
Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to reuse old session artifacts to impersonate a leg…
- CVE-2021-42545HIGHCVSS 8.1EG 8.12021-11-30
An insufficient session expiration vulnerability exists in Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27, which allows a remote attacker to reuse, spoof, or steal other user and admin sessions.
- CVE-2021-34739HIGHCVSS 8.1EG 8.12021-11-04
A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized access to the web-based m…
- CVE-2021-24019HIGHCVSS 8.1EG 8.12021-10-06
An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be ab…
- CVE-2009-20001HIGHCVSS 8.1EG 8.12021-03-07
An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an attacker who somehow ga…
- CVE-2020-23140HIGHCVSS 8.1EG 8.12020-11-09
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.
- CVE-2020-13299HIGHCVSS 8.1EG 8.12020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.
- CVE-2020-6644HIGHCVSS 8.1EG 8.12020-06-22
An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID via other, h…
- CVE-2019-1003049HIGHCVSS 8.1EG 8.12019-04-10
Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-100300…
- CVE-2017-11667HIGHCVSS 8.1EG 8.12017-07-26
OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.
- CVE-2016-8712HIGHCVSS 8.1EG 8.12017-04-13
An exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless AP running firmware 1.1. The device uses one nonce for all session authentication requests and only changes the nonce if the we…
- CVE-2021-1542HIGHCVSS 7.2EG 8.12021-06-16
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying…
- CVE-2025-36359HIGHCVSS 6.5EG 8.12026-06-30
IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.
- CVE-2018-1127HIGHCVSS 4.2EG 8.12018-09-11
Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for a few minutes allowing attackers to replay tokens acquired via sniffing/MITM attacks and …
- CVE-2025-46815HIGHCVSS 8.0EG 8.02025-05-06
The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API. This API enables the use of IdPs for authentication, known as idp intents. Following a successful idp intent, the cli…
- CVE-2025-2185HIGHCVSS 8.0EG 8.02025-04-25
ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient session expiration vulnerability, which could permit an attacker to transmit passwords over unencrypted connections, re…
- CVE-2022-33137HIGHCVSS 8.0EG 8.02022-07-12
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All versions < V3.3), SIMAT…
- CVE-2018-10990HIGHCVSS 8.0EG 8.02018-05-14
On Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices, a logout action does not immediately destroy all state on the device related to the validity of the "credential" cookie, which might make it easier for attackers to obtain ac…
- CVE-2025-15552HIGHCVSS 7.8EG 7.82026-03-16
Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.
Map vulnerabilities like CWE-613 to your infrastructure
EchelonGraph correlates every CVE — across CWE-613 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →