# CWE-613: Insufficient Session Expiration

> As of 2026-10-05, CWE-613 (Insufficient Session Expiration) underlies 8 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 10 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-613?

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

CWE-613 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Web Based; Technology: Web Server.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/613.html) (CWE-613 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Access Control** — Bypass Protection Mechanism

_Source: MITRE CWE, common consequences._

## How CWE-613 is exploited in the wild

Threadlinqs maps 8 CVEs to CWE-613, published between 2026-06-23 and 2026-09-24. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 1 critical, 1 high, 3 medium. The highest EPSS score in the set is 0.5% (CVE-2026-55250), the modelled probability of exploitation in the next 30 days. 10 tracked threats reference CWE-613 directly or through a CVE it covers; the most recent is “Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)” (2026-09-13). Affected products concentrate in CoreWCF (1), EVoke (1), Gerrit (1), among 8 vendors in total.

## Vulnerabilities (CVEs)

All 8 CVEs mapped to CWE-613, CISA KEV first, then by CVSS score.

- [CVE-2026-84480](https://intel.threadlinqs.com/cve/CVE-2026-84480) — CVSS 9.8 critical · EPSS 0.2% · published 2026-09-01
- [CVE-2026-54479](https://intel.threadlinqs.com/cve/CVE-2026-54479) — CVSS 7.3 high · EPSS 0.2% · published 2026-06-25
- [CVE-2026-55423](https://intel.threadlinqs.com/cve/CVE-2026-55423) — CVSS 6.1 medium · EPSS 0.1% · published 2026-06-23
- [CVE-2026-54779](https://intel.threadlinqs.com/cve/CVE-2026-54779) — CVSS 5.9 medium · EPSS 0.2% · published 2026-07-08
- [CVE-2026-82469](https://intel.threadlinqs.com/cve/CVE-2026-82469) — CVSS 5.4 medium · published 2026-08-29
- [CVE-2026-55250](https://intel.threadlinqs.com/cve/CVE-2026-55250) — EPSS 0.5% · published 2026-09-08
- [CVE-2026-63175](https://intel.threadlinqs.com/cve/CVE-2026-63175) — EPSS 0.2% · published 2026-07-15
- [CVE-2026-87720](https://intel.threadlinqs.com/cve/CVE-2026-87720) — EPSS 0.2% · published 2026-09-24

## Affected vendors

- [CoreWCF](https://intel.threadlinqs.com/vendors/corewcf) — 1 CVE
- **EVoke** — 1 CVE
- **Gerrit** — 1 CVE
- **Lookyloo** — 1 CVE
- [WWBN](https://intel.threadlinqs.com/vendors/wwbn) — 1 CVE
- **jeremyevans** — 1 CVE
- [langflow-ai](https://intel.threadlinqs.com/vendors/langflow-ai) — 1 CVE
- **macropay-solutions** — 1 CVE

## Threat activity

10 tracked threats cite CWE-613:

- [Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)](https://intel.threadlinqs.com/threat/TL-2026-2486) — CRITICAL · 2026-09-13
- [Anthropic Locks Out Claude Users After Commodity Infostealers (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijack Login Sessions](https://intel.threadlinqs.com/threat/TL-2026-2253) — MEDIUM · 2026-08-31
- [Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth Fail-Open Flaws — NVD Scores 5 of 11 CRITICAL/HIGH Despite Apache's Low/Moderate Ratings](https://intel.threadlinqs.com/threat/TL-2026-2159) — CRITICAL · 2026-08-26
- [CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud Enumeration (AA26-237A)](https://intel.threadlinqs.com/threat/TL-2026-2161) — HIGH · 2026-08-26
- [CVE-2026-11374: Predictable SSO Ticket Generation Enables Unauthenticated Account Takeover in ManageEngine AD360 Products](https://intel.threadlinqs.com/threat/TL-2026-1627) — CRITICAL · 2026-07-22
- [Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-0976) — CRITICAL · 2026-06-28
- [Klue SaaS Integration Platform OAuth Token Compromise – Multi-Organization Salesforce CRM Access](https://intel.threadlinqs.com/threat/TL-2026-0992) — CRITICAL · 2026-06-28
- [Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares\[.\]com / wetransfer\[.\]ICU SEO-Poisoning Operation)](https://intel.threadlinqs.com/threat/TL-2026-0799) — HIGH · 2026-06-15
- [Storm Infostealer (v0.0.2.0 Gunnar): Server-Side Browser Decryption Bypasses Chrome App-Bound Encryption and Hijacks MFA-Protected SaaS Sessions](https://intel.threadlinqs.com/threat/TL-2026-0355) — HIGH · 2026-04-13
- [EvilTokens: AI-Augmented Phishing-as-a-Service Platform Automating Microsoft 365 Device Code Phishing and BEC Fraud](https://intel.threadlinqs.com/threat/TL-2026-0328) — HIGH · 2026-04-07

## Mitigations

- **Implementation**: Set sessions/credentials expiration date.

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Automated Static Analysis** (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- CWE-672 Operation on a Resource after Expiration or Release
- [CWE-287 Improper Authentication](https://intel.threadlinqs.com/cwe/CWE-287)

Canonical: https://intel.threadlinqs.com/cwe/CWE-613
Source definition: https://cwe.mitre.org/data/definitions/613.html
Detection rules and IOCs for threats exploiting CWE-613 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
