CWE-613Base

Insufficient Session Expiration

Incomplete in the CWE catalog · 406 CVEs mapped

406
CVEs mapped
6.3
Median CVSS
What it is

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Recent examples
4.3cvss
CVE-2026-86215

CVE-2026-86215 - MEDIUM Severity Vulnerability

A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation of the argument log_out leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

MEDIUMno explanation yet
epss
5.4cvss
CVE-2026-55513

CVE-2026-55513 - MEDIUM Severity Vulnerability

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the server-wide enrollment_token_ttl security setting and per-network network_config.enrollment_token_ttl overrides. API host creation and token-regeneration paths use the configured TTL resolver, but POST /ui/hosts hardcodes now.Add(24 * time.Hour) for newly minted agent enrollment tokens. In deployments that intentionally reduce enrollment-token lifetime, any authenticated operator who can create a host through the Web UI can still mint a bearer enrollment token valid for about 24 hours. This issue has been patched in version 0.5.0.

MEDIUMno explanation yet
0%
epss
6.8cvss
CVE-2026-61608

CVE-2026-61608 - MEDIUM Severity Vulnerability

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning a leaked, forwarded, or archived invitation email can be used at any time in the future to join a company or silently add a compromised email account to a company. Version 3.0.1 fixes the issue.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-613
Abstraction
Base
Structure
Simple
Status
Incomplete
References (1)