Weaknesses of type CWE-778

36 results

Registro insuficiente de eventos de segurança

A aplicação não registra eventos críticos de segurança com detalhes suficientes para auditoria, investigação de incidentes ou detecção de ataques. Sem logs adequados, ataques podem passar despercebidos e investigações post-mortem tornam-se impossíveis.

Example

Um sistema de autenticação que falha silenciosamente em registrar tentativas de login falhadas, tentativas de acesso a áreas restritas ou mudanças em permissões de usuários. Um atacante explora a aplicação livremente sem deixar rastro auditável.

How to mitigate

Implemente logging obrigatório para eventos sensíveis: autenticação, autorização, modificações de dados críticos, erros de segurança e ações administrativas. Inclua timestamp, identificador do usuário, ação realizada e resultado; armazene logs em local seguro e imutável, separado da aplicação.

CVE-2026-76208HIGHphpMyFAQ 3.1.0 through 4.1.6 Authentication Bypass via LDAPEPSS 0.3%CVE-2026-91859MEDIUMMISP Access Log Entry Overwritten by Error Controller's Second beforeFilter PassEPSS 0.3%CVE-2025-32967MEDIUMOpenEMR doesn't log password administration properlyEPSS 0.3%CVE-2026-3494MEDIUMMariaDB Server Audit Plugin Comment Handling BypassEPSS 0.3%CVE-2026-22279MEDIUMDell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An unauthenticated attacker with remote acceEPSS 0.3%CVE-2025-53498MEDIUMLack of Audit Logging in AbuseFilterEPSS 0.2%CVE-2026-9247LOWInsufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealEPSS 0.2%CVE-2026-29812MEDIUMCyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.EPSS 0.2%CVE-2025-62307MEDIUMHCL IntelliOps Event Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2026-82863HIGH@hulumi/baseline before 1.3.2 CloudTrail Selector Tampering DetectionEPSS 0.1%CVE-2024-24901LOWDell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with high privileges couldEPSS 0.1%CVE-2025-52644MEDIUMHCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged.EPSS 0.1%CVE-2020-37268MEDIUMCoq and Rocq Prover Print Assumptions Omits Unsafe Universe Checking Inlined Through Parameter InlineEPSS 0.1%CVE-2026-90955MEDIUMMISP CLI Shell Audit Logs Lose User Identity and CLI Marker After First Lazy Model LoadEPSS 0.1%CVE-2026-32803LOWDell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 conEPSS 0.1%CVE-2026-18161MEDIUMIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS