VulnSea

CWE-613

CVEs classified under CWE-613, newest first.

71 CVEsRSS

CVE-2026-77519Medium· 5.4
yesterday

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, the /chat/api/mcp authentication path looks up an ApplicationApiKey using only its secret and active status, without enforcing the is_permanent and expire_ti…

Sunlit1Panel-dev · MaxKBvia NVD
CVE-2026-86473Critical· 9.1
yesterday

Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie

Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout …

MidnightApache Software Foundation · apache-airflowvia NVD
CVE-2026-92976Medium· 5.1
4d ago

A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite

A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. An authenticated user could inject malicious HTML or JavaScript content into the fields containing their personal data…

SunlitT-Systems · TAOEPSS 0.27%via NVD
CVE-2026-81637Low· 2.3
5d ago

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled account. AshAuthenticat…

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled account. AshAuthenticat…

Sunlitteam-alembic · ash_authenticationEPSS 0.48%via NVD
CVE-2026-86533Critical· 9.1
5d ago

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_p…

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_p…

Midnightteam-alembic · ash_authenticationEPSS 0.65%via NVD
CVE-2026-92920Medium· 5.4
5d ago

admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions

admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bearer tokens issued before account disab…

Sunlitcjbi · admin3EPSS 0.18%via NVD
CVE-2026-92800Medium· 6.8PoC
6d ago

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket s…

Twilightsuitenumerique · DocsEPSS 0.24%via NVD
CVE-2026-85387High· 7.1⚖ disputed
6d ago

Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token had been issued to

Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token had been issued to. The resource server's authorization validator confirmed only that a t…

Twilightconcretecms · concrete_cmsEPSS 0.21%via NVD
CVE-2026-92616Medium· 6.8
6d ago

FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interfa…

FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interfa…

Sunliterror311 · FileRiseEPSS 0.32%via NVD
CVE-2026-82310High· 7.2
6d ago

Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation

Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, but the Core API continues to accept an existing, u…

Twilightapache · apache-airflow-providers-fabEPSS 0.98%via NVD
CVE-2026-86462Critical· 9.1
6d ago

Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions

Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie kee…

Midnightapache · apache-airflow-providers-fabEPSS 0.80%via NVD
CVE-2026-82311Critical· 9.8
6d ago

Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does

Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login stores in the sessi…

Midnightapache · apache-airflow-providers-fabEPSS 0.95%via NVD
CVE-2026-92358Medium· 6.4
6d ago

A flaw was found in the first broker login flow of Keycloak

A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is created to validate the link. However, this proof is not properly cleared after t…

SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.28%via NVD
CVE-2026-88262High· 8.7
1w ago

Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1.

Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1.

Twilightbizwell · xClickEPSS 0.33%via NVD
CVE-2026-55617Medium· 6.9
1w ago

Hydro is a next-generation high-performance online judge platform

Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session token without deleting the previous tok…

Sunlithydro-dev · HydroEPSS 0.27%via NVD
CVE-2026-56665Medium· 4.2
1w ago

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider

Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.27%via OSV
CVE-2026-81268High· 8.1
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.

Twilightlangflow · langflowEPSS 0.31%via NVD
CVE-2026-80174Medium· 5.3
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Session Expiration vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with remote access could potentially expl…

SunlitDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.17%via CVEORG
CVE-2026-87014Medium· 6.5PoC
1w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's d…

Twilightopenwebui · open_webuiEPSS 0.29%via NVD
CVE-2026-55250High· 8.7
2w ago

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-perf…

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-perf…

Twilightmacropay-solutions · maravel-frameworkEPSS 0.55%via NVD
CVE-2026-19931Critical· 9.8PoC⚖ disputed
2w ago

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previo…

Abyssalhaxx · curlEPSS 1.2%via NVD
CVE-2026-86215Medium· 4.3PoC
2w ago

A vulnerability was identified in Mstfakts College-Management-System

A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation of the argument log_out leads to sessio…

TwilightMstfakts · College-Management-SystemEPSS 0.21%via NVD
CVE-2026-61608Medium· 6.8
2w ago

SolidInvoice is an open-source invoicing platform

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning a leaked, forwarded, or archived invitatio…

SunlitEPSS 0.24%via NVD
CVE-2026-55513Medium· 5.4PoC
2w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the server-wide enrollment_token_ttl security setting and per-networ…

Twilightforgekeep · nebula-meshEPSS 0.19%via NVD
CVE-2026-53602Medium
2w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does n…

Sunlitforgekeep · github.com/forgekeep/nebula-meshEPSS 0.22%via NVD
CVE-2026-84480Critical· 9.8
3w ago

WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely

WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any t…

MidnightEPSS 0.29%via NVD
CVE-2026-84203High· 8.1
3w ago

Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access

Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new acc…

TwilightEPSS 0.26%via NVD
CVE-2026-82469Medium· 5.4
3w ago

Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token

Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via non-POST m…

SunlitEPSS 0.24%via NVD
CVE-2026-65984High· 7.5
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in server/api/auth/index.js falls back from current user data to decoded.groups, including when the user is deleted or grou…

Twilightfrangoteam · FUXAEPSS 0.47%via NVD
CVE-2026-45791Medium· 5.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.update procedure in apps/dokploy/server/api/routers/user.ts updates account.password without deleting other rows from session, allowing a comp…

SunlitEPSS 0.41%via NVD
CWE-613 vulnerabilities (CVEs) · VulnSea