Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-613 (不充分的会话过期机制) — Vulnerability Class 414

414 vulnerabilities classified as CWE-613 (不充分的会话过期机制). AI Chinese analysis included.

CWE-613 represents a critical authentication weakness where web applications fail to properly invalidate session identifiers after a user logs out or after a period of inactivity. This flaw allows attackers to exploit stale session tokens, often obtained through network sniffing, session fixation, or simply waiting for a user to abandon a shared device. By reusing these expired credentials, adversaries can bypass authentication mechanisms and gain unauthorized access to sensitive user accounts or administrative functions without needing to crack passwords. To mitigate this risk, developers must implement robust session management protocols that enforce strict expiration policies. This includes setting appropriate timeout durations for both active and idle sessions, ensuring that logout actions immediately invalidate server-side session data, and utilizing secure, HttpOnly cookies to prevent client-side script access to session identifiers.

MITRE CWE Description
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Common Consequences (1)
Access Control Bypass Protection Mechanism
Mitigations (1)
Implementation Set sessions/credentials expiration date.
Examples (1)
The following snippet was taken from a J2EE web.xml deployment descriptor in which the session-timeout parameter is explicitly defined (the default value depends on the container). In this case the value is set to -1, which means that a session will never expire.
<web-app> [...snipped...] <session-config> <session-timeout>-1</session-timeout> </session-config> </web-app>
Bad · Java
CVE ID Title CVSS Severity Published
CVE-2026-102367 mall4j through 4.0 Insufficient Session Expiration via Token Refresh — mall4j 5.4 Medium 2026-09-28
CVE-2026-88805 Session Not Revoked Server-Side on Logout in Rancher — Rancher 8.1 High 2026-09-28
CVE-2026-100711 froxlor before 2.3.12 Authentication Bypass via Session Persistence — froxlor 7.5 High 2026-09-26
CVE-2026-100624 Capgo.app before 12.264.5 Upload Expiry Bypass via build upload — capgo.app 5.4 Medium 2026-09-26
CVE-2026-100554 OpenClaw before 2026.8.1 Canvas Capability Revocation Bypass — OpenClaw 4.2 Medium 2026-09-26
CVE-2026-100502 Flame through 2.4.0 Admin Token Insufficient Session Expiration — flame 5.0 Medium 2026-09-25
CVE-2026-67242 RabbitMQ: OAuth2 is_integer(Exp) guard skips token-expiry checks for float exp — rabbitmq-server 6.3 Medium 2026-09-25
CVE-2026-82566 Botslab G980H Dashcams Insufficient session expiration — G980H 8.8 High 2026-09-24
CVE-2026-97056 SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass — signoz 6.8 Medium 2026-09-24
CVE-2026-73586 Dell SCG Policy Manager会话过期提权漏洞 — Secure Connect Gateway (SCG) Policy Manager 6.4 Medium 2026-09-23
CVE-2026-92378 uniFLOW Online Legacy UI Previous login session retained when entering Reduced Function Login — uniFLOW Online 4.1 Medium 2026-09-23
CVE-2026-86698 Refresh tokens accepted as private repository credentials at the CDN — hexpm 2.3 Low 2026-09-22
CVE-2026-77519 MaxKB: Expired application API keys remain usable on `/chat/api/mcp` — MaxKB 5.4 Medium 2026-09-21
CVE-2026-86473 Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry — Apache Airflow - - 2026-09-21
CVE-2026-92976 Stored Cross-Site Scripting (XSS) in T-Systems’ TAO 2.0 — TAO 5.1 Medium 2026-09-18
CVE-2026-86533 Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix — ash_authentication 9.1 Critical 2026-09-17
CVE-2026-81637 Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication — ash_authentication 2.3 Low 2026-09-17
CVE-2026-92920 admin3 through 3.0.0 Session Not Invalidated When a User Account Is Disabled — admin3 5.4 Medium 2026-09-17
CVE-2026-92800 Docs before 5.4.1 Stale Collaboration Session After Access Revocation — Docs 6.8 Medium 2026-09-16
CVE-2026-85387 Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API access — Concrete CMS 2.0 Low 2026-09-16
CVE-2026-92616 FileRise < 3.28.0 Privilege Escalation via WebDAV Session Inheritance — FileRise 6.8 Medium 2026-09-16
CVE-2026-82310 Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access — Apache Airflow FAB provider - - 2026-09-16
CVE-2026-86462 Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions — Apache Airflow FAB provider - - 2026-09-16
CVE-2026-82311 Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false — Apache Airflow FAB provider - - 2026-09-16
CVE-2026-92358 Keycloak-services: keycloak-services: residual cross-browser account-link proof allows silent re-linking — Red Hat Build of Keycloak 6.4 Medium 2026-09-16
CVE-2026-55617 Hydro: Insufficient session expiration when recreating sessions — Hydro 6.9 Medium 2026-09-15
CVE-2026-88262 bizwell xClick 会话机制问题漏洞 — xClick 8.7 High 2026-09-15
CVE-2026-81268 Langflow is vulnerable to authentication bypass and insufficient session expiration — Langflow OSS 8.1 High 2026-09-10
CVE-2026-87014 Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes — open-webui 6.5 Medium 2026-09-09
CVE-2026-80174 Dell Secure Connect Gateway 会话机制问题漏洞 — Secure Connect Gateway 5.0 - Application 5.3 Medium 2026-09-09

Vulnerabilities classified as CWE-613 (不充分的会话过期机制) represent 414 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.