Threats Tagged 'cwe-613'
View all threats tagged with 'cwe-613'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-613'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-49277: CWE-613: Insufficient Session Expiration in RocketChat Rocket.ChatCVE-2026-49277 0 Rocket.Chat versions prior to 7.10.12, 7.13.8, 8.0.6, 8.1.5, 8.2.4, 8.3.4, 8.4.2, and 8.5.0 do not revoke OAuth bearer or refresh tokens when a user is deactivated. This allows a deactivated user to continue using existing OAuth access tokens and mint new access tokens from existing refresh tokens. The issue is addressed in the specified fixed versions. Join the discussion | CVE Database V5 | 06/24/2026, 21:04:09 UTC Added: 06/24/2026, 21:32:18 UTC |
CVE-2026-45757: CWE-613: Insufficient Session Expiration in RocketChat Rocket.ChatCVE-2026-45757 0 Rocket.Chat versions prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12 allow users deactivated for idleness to continue using previously issued login tokens. This insufficient session expiration issue enables inactive users to access authenticated REST endpoints despite administrative deactivation. The vulnerability is classified under CWE-613 and has a low CVSS score of 2.3. Fixes have been released in the specified versions. Join the discussion | CVE Database V5 | 06/24/2026, 21:01:56 UTC Added: 06/24/2026, 21:32:18 UTC |
CVE-2026-54321: CWE-613: Insufficient Session Expiration in daytonaio daytonaCVE-2026-54321 0 Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0 until 0.184.0, sandbox previews that were switched from public to private could remain reachable without authentication for a short period after the change, due to a cached visibility state that was not invalidated when the sandbox's visibility changed. This vulnerability is fixed in 0.184.0. Join the discussion | CVE Database V5 | 06/23/2026, 18:10:05 UTC Added: 06/23/2026, 18:54:13 UTC |
CVE-2026-55423: CWE-613: Insufficient Session Expiration in langflow-ai langflowCVE-2026-55423 0 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in. This vulnerability is fixed in 1.7.0. Join the discussion | CVE Database V5 | 06/23/2026, 16:27:19 UTC Added: 06/23/2026, 16:39:54 UTC |
CVE-2025-62340: CWE-613 Insufficient session expiration in HCL Software iControlCVE-2025-62340 0 HCL Software iControl version 4.2.0 is affected by an insufficient session expiration vulnerability (CWE-613). This issue occurs when the web application does not automatically terminate user sessions after a period of inactivity, potentially allowing sessions to remain active longer than intended. The vulnerability has a low severity rating with a CVSS score of 3.1. No official patch or remediation guidance has been provided by the vendor at this time. Join the discussion | CVE Database V5 | 06/17/2026, 12:17:23 UTC Added: 06/17/2026, 12:46:18 UTC |
CVE-2026-46401: CWE-613: Insufficient Session Expiration in haxtheweb issuesCVE-2026-46401 0 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.0 suffer from an improper session termination vulnerability where authentication tokens remain valid after user logout. This allows attackers who obtain valid tokens to maintain persistent access to authenticated CMS functionality, bypassing the intended session termination mechanism and enabling unauthorized access to CMS metadata and administrative functions. Version 26.0.0 fixes the issue. Join the discussion | CVE Database V5 | 06/05/2026, 19:18:05 UTC Added: 06/05/2026, 19:33:38 UTC |
CVE-2026-48726: CWE-613: Insufficient Session Expiration in Apache Software Foundation Apache AirflowCVE-2026-48726 0 A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow for `FabAuthManager` and `KeycloakAuthManager` did not actually reach the underlying `revoke_token()` call, so the JWT remained accepted by the API server until its natural expiry. An attacker holding a previously-issued JWT for a logged-out user could continue to make authenticated API calls as that user. Affects deployments configured with `FabAuthManager` or `KeycloakAuthManager` (the bug does not affect SimpleAuthManager). This is a residual gap in the fix for CVE-2025-57735, which addressed cookie-side invalidation in PR #57992 / PR #61339 but did not cover the provider-side `revoke_token()` reachability in the FAB / Keycloak code paths. Users who already upgraded for CVE-2025-57735 should additionally upgrade to `apache-airflow` 3.2.2 or later to cover the FAB / Keycloak logout paths. Join the discussion | CVE Database V5 | 06/01/2026, 07:35:19 UTC Added: 06/01/2026, 09:18:45 UTC |
Showing 1 to 7 of 7 results