Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-613 (不充分的会话过期机制) — Vulnerability Class 414

414 vulnerabilities classified as CWE-613 (不充分的会话过期机制). AI Chinese analysis included.

CWE-613 represents a critical authentication weakness where web applications fail to properly invalidate session identifiers after a user logs out or after a period of inactivity. This flaw allows attackers to exploit stale session tokens, often obtained through network sniffing, session fixation, or simply waiting for a user to abandon a shared device. By reusing these expired credentials, adversaries can bypass authentication mechanisms and gain unauthorized access to sensitive user accounts or administrative functions without needing to crack passwords. To mitigate this risk, developers must implement robust session management protocols that enforce strict expiration policies. This includes setting appropriate timeout durations for both active and idle sessions, ensuring that logout actions immediately invalidate server-side session data, and utilizing secure, HttpOnly cookies to prevent client-side script access to session identifiers.

MITRE CWE Description
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Common Consequences (1)
Access Control Bypass Protection Mechanism
Mitigations (1)
Implementation Set sessions/credentials expiration date.
Examples (1)
The following snippet was taken from a J2EE web.xml deployment descriptor in which the session-timeout parameter is explicitly defined (the default value depends on the container). In this case the value is set to -1, which means that a session will never expire.
<web-app> [...snipped...] <session-config> <session-timeout>-1</session-timeout> </session-config> </web-app>
Bad · Java
CVE ID Title CVSS Severity Published
CVE-2026-86215 Mstfakts College-Management-System Logout server.php session expiration — College-Management-System 4.3 Medium 2026-09-06
CVE-2026-55513 nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens — nebula-mesh 5.4 Medium 2026-09-04
CVE-2026-61608 SolidInvoice's user invitation tokens have no expiry, allowing indefinite unauthorized company access via leaked or old invitation links — SolidInvoice 6.8 Medium 2026-09-04
CVE-2026-84480 WWBN AVideo Password Recovery Token Expiration Bypass — AVideo 9.8 Critical 2026-09-01
CVE-2026-84203 Memos 0.26.0 through 0.30.0 Insufficient Session Expiration on Password Change — memos 8.1 High 2026-09-01
CVE-2026-82909 QuantumNous new-api Revoked API Token token session expiration — new-api 4.3 Medium 2026-08-31
CVE-2026-82469 Rodauth before 2.47.0 Authentication Bypass via jwt_refresh — rodauth 5.4 Medium 2026-08-29
CVE-2026-81826 Flowintel Fails to Invalidate Active Sessions After Password Change — flowintel 9.1 Critical 2026-08-27
CVE-2025-62342 HCL IntelliOps Event Management is affected by multiple security vulnerabilities. — IEM 6.4 Medium 2026-08-27
CVE-2026-73180 Apache Tomcat: Authenticated WebSocket session survives end of HTTP session — Apache Tomcat - - 2026-08-25
CVE-2026-79664 Ech0 before 4.7.3 Access Token Revocation Bypass — Ech0 7.4 High 2026-08-25
CVE-2026-77130 Insufficient Session Expiration in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy) — Extension "SYSSY - TYPO3 Monitoring & Security Checks" 5.3 Medium 2026-08-25
CVE-2026-75554 Explicit organization scopes survive token refresh after membership ends — hexpm 2.3 Low 2026-08-24
CVE-2026-14950 Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insufficient Session Expiration due to flawed session expiration logic — FDS 102 9.8 Critical 2026-08-20
CVE-2026-65984 FUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged sessions — FUXA 7.5 High 2026-08-18
CVE-2026-45791 Dokploy: Password Change Does Not Revoke Active Sessions — dokploy 5.9 Medium 2026-08-17
CVE-2026-73611 File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass — filebrowser 6.8 Medium 2026-08-13
CVE-2026-66376 Deleted users may temporarily retain access to JFrog Artifactory — artifactory 4.2 Medium 2026-08-12
CVE-2026-17600 Nexus Repository 3 - Session Not Invalidated on User Account Deletion or Deactivation — Nexus Repository 3 8.7 High 2026-08-07
CVE-2026-48079 OpenReception's logout page clears local access_token before server-side revocation, leaving duplicated tokens valid until expiry — appointment-booking-software 7.4 High 2026-08-06
CVE-2025-12317 Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access Privileges — WSO2 Enterprise Integrator 5.0 Medium 2026-08-06
CVE-2025-12627 Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server Enables Continued Unauthorized Actions — WSO2 Identity Server 2.4 Low 2026-08-06
CVE-2024-8995 Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access — WSO2 API Manager 4.9 Medium 2026-08-06
CVE-2026-60053 Apache Answer: Residual Administrative API Key Access After Role or Account Revocation — Apache Answer - - 2026-08-05
CVE-2026-39924 Flarum < 1.8.16 Session Persistence via Improper Access Token Revocation — Flarum Framework 6.8 Medium 2026-08-05
CVE-2026-71206 shiori - JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion — shiori 8.2 High 2026-08-05
CVE-2026-14465 Session Fixation in Bilin Software's HUMANIST Digital Human Resources — HUMANIST Digital Human Resources 6.5 Medium 2026-08-04
CVE-2024-40683 IBM Operations Analytics - Log Analysis is affected by a TOCTOU weakness allowing active sessions to persist beyond a password change — Operations Analytics - Log Analysis 6.3 Medium 2026-07-30
CVE-2026-14227 Insufficient session expiration in MikroTik RouterOS — RouterOS 4.9 Medium 2026-07-30
CVE-2026-16970 DFIR-IRIS Insufficient Logout Implementation — iris-web 4.2 Medium 2026-07-30

Vulnerabilities classified as CWE-613 (不充分的会话过期机制) represent 414 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.