CWE-613: Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
406 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-59841 — FlagForgeCTF's Improper Session Handling Allows Access After Logout
- CVE-2025-24973 — Concorde not removing authentication tokens after logging out
- CVE-2026-1435 — Incorrect management of session invalidation vulnerability in Graylog Web Interface
- CVE-2024-13996 — Nagios XI < 2024R1.1.3 Session Not Invalidated After Password Change
- CVE-2026-27575 — Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change
- CVE-2024-39809 — BIG-IP Next Central Manager vulnerability
- CVE-2026-34572 — CI4MS: Account Deactivation Module Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
- CVE-2025-54592 — FreshRSS has Incomplete Session Termination on Logout
- CVE-2025-40566 — A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All ve
- CVE-2024-5995 — Soar Cloud HR Portal - Insufficient Session Expiration
- CVE-2026-24894 — FrankenPHP leaks session data between requests in worker mode
- CVE-2025-66289 — OrangeHRM is Vulnerable to Persistent Session Access Due to Missing Invalidation After User Disable and Password Change
- CVE-2025-49152 — Insufficient Session Expiration in MICROSENS NMP Web+
- CVE-2024-43685 — Session token fixation in TimeProvider 4100
- CVE-2025-2185 — ALBEDO Telecom Net.Time - PTP/NTP Clock Insufficient Session Expiration
- CVE-2025-66223 — OpenObserve's Invite Token Lifecycle Misconfiguration
- CVE-2025-42602 — Improper Authentication Vulnerability in Meon KYC solutions
- CVE-2026-73180 — Apache Tomcat: Authenticated WebSocket session survives end of HTTP session
- CVE-2026-46455 — Apache Camel: Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted
- CVE-2026-28564 — Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
Recently published
- CVE-2026-80174 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-55250 — Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Tagged Caches
- CVE-2026-86215 — Mstfakts College-Management-System Logout server.php session expiration
- CVE-2026-55513 — nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens
- CVE-2026-61608 — SolidInvoice's user invitation tokens have no expiry, allowing indefinite unauthorized company access via leaked or old invitation links
- CVE-2026-84480 — WWBN AVideo Password Recovery Token Expiration Bypass
- CVE-2026-84203 — Memos 0.26.0 through 0.30.0 Insufficient Session Expiration on Password Change
- CVE-2026-82909 — QuantumNous new-api Revoked API Token token session expiration
- CVE-2026-82469 — Rodauth before 2.47.0 Authentication Bypass via jwt_refresh
- CVE-2026-81826 — Flowintel Fails to Invalidate Active Sessions After Password Change
- CVE-2025-62342 — HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
- CVE-2026-73180 — Apache Tomcat: Authenticated WebSocket session survives end of HTTP session
- CVE-2026-79664 — Ech0 before 4.7.3 Access Token Revocation Bypass
- CVE-2026-77130 — Insufficient Session Expiration in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)
- CVE-2026-75554 — Explicit organization scopes survive token refresh after membership ends
- CVE-2026-14950 — Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insufficient Session Expiration due to flawed session expiration logic
- CVE-2026-65984 — FUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged sessions
- CVE-2026-45791 — Dokploy: Password Change Does Not Revoke Active Sessions
- CVE-2026-73611 — File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass
- CVE-2026-66376 — Deleted users may temporarily retain access to JFrog Artifactory