An Insufficient Session Expiration vulnerability [CWE-613...
        
  Moderate severity
        
          Unreviewed
      
        Published
          Oct 14, 2025 
          to the GitHub Advisory Database
          •
          Updated Oct 14, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Oct 14, 2025 
    
  
        Published to the GitHub Advisory Database
      Oct 14, 2025 
    
  
        Last updated
      Oct 14, 2025 
    
  
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possession of the SAML record of a user session to access or re-open that session via re-use of SAML record.
References