CWE-613— Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."— MITRE CWE catalog
664 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-613page 7 of 14
- CVE-2024-45187HIGHCVSS 7.1EG 7.12024-08-23
Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute arbitrary code through the Mage AI terminal server
- CVE-2023-37504HIGHCVSS 7.1EG 7.12023-10-19
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called. If the session identifier can be discovered, it could be replayed to the ap…
- CVE-2021-3461HIGHCVSS 7.1EG 7.12022-04-01
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].
- CVE-2022-0991HIGHCVSS 7.1EG 7.12022-03-19
Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9.
- CVE-2022-24743HIGHCVSS 7.1EG 7.12022-03-14
Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set to null after the password was changed. The same token could be used several times, which could result in leak of the e…
- CVE-2020-10709HIGHCVSS 7.1EG 7.12021-05-27
A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authentication. This flaw allows an attacker to obtain a refresh token that does not expire. The…
- CVE-2020-5774HIGHCVSS 7.1EG 7.12020-08-21
Nessus versions 8.11.0 and earlier were found to maintain sessions longer than the permitted period in certain scenarios. The lack of proper session expiration could allow attackers with local access to login into an existing browser sessi…
- CVE-2019-2386HIGHCVSS 7.1EG 7.12019-08-06
After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and become conflated with new accounts, if those accounts reuse the names of deleted ones. This iss…
- CVE-2026-54321HIGHCVSS 7.0EG 7.02026-06-16
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0 until 0.184.0, sandbox previews that were switched from public to private could remain reachable without authenticatio…
- CVE-2020-1762HIGHCVSS 7.0EG 7.02020-04-27
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user s…
- CVE-2026-55617MEDIUMCVSS 6.9EG 6.92026-06-18
Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session token without deleting the previous token…
- CVE-2025-61775MEDIUMCVSS 6.9EG 6.92025-10-13
Vickey is a Misskey-based microblogging platform. A vulnerability exists in Vickey prior to version 2025.10.0 where unexpired email confirmation links can be reused multiple times to send repeated confirmation emails to a verified email ad…
- CVE-2023-25562MEDIUMCVSS 6.9EG 6.92023-02-11
DataHub is an open-source metadata platform. In versions of DataHub prior to 0.8.45 Session cookies are only cleared on new sign-in events and not on logout events. Any authentication checks using the `AuthUtils.hasValidSessionCookie()` me…
- CVE-2026-107275MEDIUMCVSS 6.8EG 6.82026-10-08
@fastify/jwt is a JSON Web Token plugin for the Fastify web framework. In versions before 10.2.3, a time span passed to expiresIn, notBefore, or maxAge that the plugin's parser cannot read, such as a compound span, a month unit, an ISO 860…
- CVE-2026-103279MEDIUMCVSS 6.8EG 6.82026-10-01
Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access to user accounts even after the associated user changes their password.
- CVE-2026-97056MEDIUMCVSS 6.8EG 6.82026-09-24
SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which was not the default before v0.143.0), do not revoke a user's existing login sessions when the user's password is re…
- CVE-2026-92800MEDIUMCVSS 6.8EG 6.82026-09-16
Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket ses…
- CVE-2026-92616MEDIUMCVSS 6.8EG 6.82026-09-16
FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interface…
- CVE-2026-61608MEDIUMCVSS 6.8EG 6.82026-09-04
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning a leaked, forwarded, or archived invitation …
- CVE-2026-73180MEDIUMCVSS 6.8EG 6.82026-08-25
Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokce…
- CVE-2026-73611MEDIUMCVSS 6.8EG 6.82026-08-13
File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrativ…
- CVE-2026-39924MEDIUMCVSS 6.8EG 6.82026-08-05
Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is never…
- CVE-2026-52809MEDIUMCVSS 6.8EG 6.82026-06-23
Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.ActivateCodeLives (the account-activation lifetime), not conf.Auth.ResetPasswordCodeLives. The token lifetime is baked int…
- CVE-2026-9802MEDIUMCVSS 6.8EG 6.82026-05-28
A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refr…
- CVE-2026-43911MEDIUMCVSS 6.8EG 6.82026-05-11
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive operations (password change, KDF change, key rotation, e…
- CVE-2026-40934MEDIUMCVSS 6.8EG 6.82026-05-05
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and is never r…
- CVE-2026-40939MEDIUMCVSS 6.8EG 6.82026-04-21
The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity timeout. Sessions persisted indefinitely…
- CVE-2026-27933MEDIUMCVSS 6.8EG 6.82026-02-26
Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Versions prior to 0.133.0 are vulnerable to session hijack via cookie leakage in proxy caches. Version 0.1…
- CVE-2024-11627MEDIUMCVSS 6.8EG 6.82025-01-07
: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400…
- CVE-2022-3916MEDIUMCVSS 6.8EG 6.82023-09-20
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root an…
- CVE-2023-40174MEDIUMCVSS 6.8EG 6.82023-08-18
Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Insufficient session expiration is a web application security vulnerability that occurs when a web application does n…
- CVE-2023-22771MEDIUMCVSS 6.8EG 6.82023-03-01
An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability allows an attacker to keep a session running on an affected device after the removal of the impact…
- CVE-2020-15218MEDIUMCVSS 6.8EG 6.82021-01-13
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back button. This is fixed in versions 2.7.2 …
- CVE-2020-15774MEDIUMCVSS 6.8EG 6.82020-09-18
An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. An attacker with physical access to the browser of a user who has recently logged in to Gradle Enterprise and since closed their browser could reopen their browser to access G…
- CVE-2024-27779MEDIUMCVSS 6.7EG 6.72025-07-18
An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version 4.2.6 and below, 4.0 all versions, 3.2 all versions and FortiIsolator version 2.4 and below, 2.3 all versions, 2.2 all…
- CVE-2025-4407MEDIUMCVSS 6.7EG 6.72025-06-30
Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel Pro: through 1.0.1.
- CVE-2023-28003MEDIUMCVSS 6.7EG 6.72023-04-18
A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized access over a hijacked session in PME after the legitimate user has signed out of their account.
- CVE-2019-11106MEDIUMCVSS 6.7EG 6.72019-12-18
Insufficient session validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privil…
- CVE-2026-3401MEDIUMCVSS 6.6EG 6.62026-03-02
A weakness has been identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part. This manipulation causes session expiration. Remote exploitation of the attack is possible. The complexity of …
- CVE-2024-25051MEDIUMCVSS 6.6EG 6.62025-04-02
IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system.
- CVE-2024-0008MEDIUMCVSS 6.6EG 6.62024-02-14
Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.
- CVE-2020-1666MEDIUMCVSS 6.6EG 6.62020-10-16
The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the console cable is disconnected. This could allow a malicious attacker with physical access …
- CVE-2018-2451MEDIUMCVSS 6.6EG 6.62018-08-14
XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentional prolonged period of validity. Consequently, a platform user could access controller re…
- CVE-2026-87014MEDIUMCVSS 6.5EG 6.52026-09-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's dat…
- CVE-2026-14465MEDIUMCVSS 6.5EG 6.52026-08-04
Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). This issue affects HUMANIST Digital Human Resources: from 2…
- CVE-2026-9705MEDIUMCVSS 6.5EG 6.52026-06-25
A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disa…
- CVE-2026-53830MEDIUMCVSS 6.5EG 6.52026-06-12
OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to remain active after secrets.reload. Attackers can exploit the stale-secret window to deliver we…
- CVE-2026-53824MEDIUMCVSS 6.5EG 6.52026-06-12
OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to continue executing commands during monitor refresh windows. Attackers can exploit stale token acceptance to invoke slash comm…
- CVE-2026-48726MEDIUMCVSS 6.5EG 6.52026-06-01
A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow for `FabAuthManager` and `KeycloakAuthManager` did not actually reach the underlying `r…
- CVE-2026-22706MEDIUMCVSS 6.5EG 6.52026-05-14
Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not invalidate the user's existing refresh-token sessions by default. The refresh-token invalidati…
Map vulnerabilities like CWE-613 to your infrastructure
EchelonGraph correlates every CVE — across CWE-613 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →