CVE-2026-79313
9.8 CRITICALpublic exploit availablePublished 2026-09-22 · Updated 2026-09-22
AI risk analysis
- Summary
- The flaw allows an attacker to replay an expired session, gaining unauthorized access to protected resources. This is critical as it bypasses the intended session expiration mechanism.
- Exploitability
- Exploitation is relatively straightforward if an attacker has access to a valid session cookie. The attacker must wait for the session to expire and then replay it.
- Blast radius
- If exploited, the attacker can access protected resources, potentially leading to data theft or system compromise.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to web.py 0.77 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result, an expired session whose record has not yet been cleaned up can still be replayed and used, allowing an attacker holding a previously valid session cookie to continue accessing protected resources after the configured idle timeout.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-613
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-14465
- CRITICALCVE-2026-82311PoC
- CRITICALCVE-2026-86462PoC
- CRITICALCVE-2026-86473PoC
- CRITICALCVE-2025-15399
- HIGHCVE-2025-51457
- CRITICALCVE-2025-66455PoC
- MEDIUMCVE-2025-71420PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.