CVE-2026-1815
Insufficient Session Expiration in TEİAŞ Mobile App Enables Session Hijacking
Publication date: 2026-05-21
Last updated on: 2026-05-21
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| teias | mobile_application | From 1.6.2 (inc) to 1.13 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-613 | According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization." |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an insufficient session expiration issue in the Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application. It allows an attacker to perform session hijacking, meaning the attacker can take over a user's active session due to the application not properly expiring sessions.
How can this vulnerability impact me? :
The vulnerability can lead to session hijacking, which means an attacker could gain unauthorized access to a user's session within the TEİAŞ Mobile Application. This could result in unauthorized actions or access to sensitive information associated with the user's session.