What is CWE-613?
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
CWE-613 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Web Based; Technology: Web Server.
Source: MITRE CWE (CWE-613 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Access Control — Bypass Protection Mechanism
Source: MITRE CWE, common consequences.
How CWE-613 is exploited in the wild
Threadlinqs maps 8 CVEs to CWE-613, published between 2026-06-23 and 2026-09-24. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 1 critical, 1 high, 3 medium. The highest EPSS score in the set is 0.5% (CVE-2026-55250), the modelled probability of exploitation in the next 30 days. 10 tracked threats reference CWE-613 directly or through a CVE it covers; the most recent is “Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)” (2026-09-13). Affected products concentrate in CoreWCF (1), EVoke (1), Gerrit (1), among 8 vendors in total.
Vulnerabilities (CVEs)
All 8 CVEs mapped to CWE-613, CISA KEV first, then by CVSS score.
- CVE-2026-84480 — CVSS 9.8 critical · EPSS 0.2% · published 2026-09-01
- CVE-2026-54479 — CVSS 7.3 high · EPSS 0.2% · published 2026-06-25
- CVE-2026-55423 — CVSS 6.1 medium · EPSS 0.1% · published 2026-06-23
- CVE-2026-54779 — CVSS 5.9 medium · EPSS 0.2% · published 2026-07-08
- CVE-2026-82469 — CVSS 5.4 medium · published 2026-08-29
- CVE-2026-55250 — EPSS 0.5% · published 2026-09-08
- CVE-2026-63175 — EPSS 0.2% · published 2026-07-15
- CVE-2026-87720 — EPSS 0.2% · published 2026-09-24
Affected vendors
- CoreWCF — 1 CVE
- EVoke — 1 CVE
- Gerrit — 1 CVE
- Lookyloo — 1 CVE
- WWBN — 1 CVE
- jeremyevans — 1 CVE
- langflow-ai — 1 CVE
- macropay-solutions — 1 CVE
Threat activity
10 tracked threats cite CWE-613:
- Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)CRITICAL
- Anthropic Locks Out Claude Users After Commodity Infostealers (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijack Login SessionsMEDIUM
- Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth Fail-Open Flaws — NVD Scores 5 of 11 CRITICAL/HIGH Despite Apache's Low/Moderate RatingsCRITICAL
- CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud Enumeration (AA26-237A)HIGH
- CVE-2026-11374: Predictable SSO Ticket Generation Enables Unauthenticated Account Takeover in ManageEngine AD360 ProductsCRITICAL
- Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data ExfiltrationCRITICAL
- Klue SaaS Integration Platform OAuth Token Compromise – Multi-Organization Salesforce CRM AccessCRITICAL
- Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares[.]com / wetransfer[.]ICU SEO-Poisoning Operation)HIGH
- Storm Infostealer (v0.0.2.0 Gunnar): Server-Side Browser Decryption Bypasses Chrome App-Bound Encryption and Hijacks MFA-Protected SaaS SessionsHIGH
- EvilTokens: AI-Augmented Phishing-as-a-Service Platform Automating Microsoft 365 Device Code Phishing and BEC FraudHIGH
Mitigations
- Implementation: Set sessions/credentials expiration date.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.