Threadlinqs IntelligenceStart free

Weakness · BaseCWE-613

CWE-613: Insufficient Session Expiration

Base

As of 2026-10-05, CWE-613 (Insufficient Session Expiration) underlies 8 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 10 tracked threats.

CVEs
8Mapped to CWE-613
CISA KEV
0None listed yet
Critical
1CVSS v3 critical CVEs
Threats
10Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-613?

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

CWE-613 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Web Based; Technology: Web Server.

Source: MITRE CWE (CWE-613 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Access Control — Bypass Protection Mechanism

Source: MITRE CWE, common consequences.

How CWE-613 is exploited in the wild

Threadlinqs maps 8 CVEs to CWE-613, published between 2026-06-23 and 2026-09-24. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 1 critical, 1 high, 3 medium. The highest EPSS score in the set is 0.5% (CVE-2026-55250), the modelled probability of exploitation in the next 30 days. 10 tracked threats reference CWE-613 directly or through a CVE it covers; the most recent is “Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)” (2026-09-13). Affected products concentrate in CoreWCF (1), EVoke (1), Gerrit (1), among 8 vendors in total.

Vulnerabilities (CVEs)

All 8 CVEs mapped to CWE-613, CISA KEV first, then by CVSS score.

Affected vendors

  • CoreWCF — 1 CVE
  • EVoke — 1 CVE
  • Gerrit — 1 CVE
  • Lookyloo — 1 CVE
  • WWBN — 1 CVE
  • jeremyevans — 1 CVE
  • langflow-ai — 1 CVE
  • macropay-solutions — 1 CVE

Threat activity

10 tracked threats cite CWE-613:

Mitigations

  • Implementation: Set sessions/credentials expiration date.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.