An insufficient session expiration vulnerability [CWE-613...
        
  Moderate severity
        
          Unreviewed
      
        Published
          Jul 18, 2025 
          to the GitHub Advisory Database
          •
          Updated Jul 18, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Jul 18, 2025 
    
  
        Published to the GitHub Advisory Database
      Jul 18, 2025 
    
  
        Last updated
      Jul 18, 2025 
    
  
An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version 4.2.6 and below, 4.0 all versions, 3.2 all versions and FortiIsolator version 2.4 and below, 2.3 all versions, 2.2 all versions, 2.1 all versions, 2.0 all versions, 1.2 all versions may allow a remote attacker in possession of an admin session cookie to keep using that admin's session even after the admin user was deleted.
References