← Back to search

CVE-2026-79313

9.8 CRITICALpublic exploit available

Published 2026-09-22 · Updated 2026-09-22

AI risk analysis

Summary
The flaw allows an attacker to replay an expired session, gaining unauthorized access to protected resources. This is critical as it bypasses the intended session expiration mechanism.
Exploitability
Exploitation is relatively straightforward if an attacker has access to a valid session cookie. The attacker must wait for the session to expire and then replay it.
Blast radius
If exploited, the attacker can access protected resources, potentially leading to data theft or system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to web.py 0.77 or later.
auth-bypasswebsession-expiration

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result, an expired session whose record has not yet been cleaned up can still be replayed and used, allowing an attacker holding a previously valid session cookie to continue accessing protected resources after the configured idle timeout.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-613

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.