Fallos del tipo CWE-778

35 resultados

Registro de eventos insuficiente

A aplicação não registra adequadamente eventos de segurança relevantes (autenticação, autorização, operações críticas, erros), dificultando detecção de ataques, investigação forense e conformidade. Sem logs suficientes, você não consegue saber o que aconteceu na sua aplicação quando algo dá errado.

Ejemplo

Um sistema aceita múltiplas tentativas de login falhadas sem registrá-las; quando uma conta é comprometida, não há rastro de quando ou como o atacante entrou. Ou uma API crítica altera dados de usuários sem registrar quem fez, quando e o quê foi alterado.

Cómo mitigar

Implemente logs estruturados (JSON, formato padronizado) de eventos de segurança: tentativas de autenticação, mudanças de autorização, operações em dados sensíveis, erros de validação. Garanta que os logs sejam armazenados com integridade (imutáveis ou em destino seguro) e revisados periodicamente. Use níveis de severidade (INFO, WARNING, ERROR) para filtrar o relevante.

CVE-2026-76208HIGHphpMyFAQ 3.1.0 through 4.1.6 Authentication Bypass via LDAPEPSS 0.3%CVE-2026-91859MEDIUMMISP Access Log Entry Overwritten by Error Controller's Second beforeFilter PassEPSS 0.3%CVE-2025-32967MEDIUMOpenEMR doesn't log password administration properlyEPSS 0.3%CVE-2026-3494MEDIUMMariaDB Server Audit Plugin Comment Handling BypassEPSS 0.3%CVE-2026-22279MEDIUMDell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An unauthenticated attacker with remote acceEPSS 0.3%CVE-2025-53498MEDIUMLack of Audit Logging in AbuseFilterEPSS 0.2%CVE-2026-9247LOWInsufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealEPSS 0.2%CVE-2026-29812MEDIUMCyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.EPSS 0.2%CVE-2025-62307MEDIUMHCL IntelliOps Event Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2026-82863HIGH@hulumi/baseline before 1.3.2 CloudTrail Selector Tampering DetectionEPSS 0.1%CVE-2024-24901LOWDell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with high privileges couldEPSS 0.1%CVE-2025-52644MEDIUMHCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged.EPSS 0.1%CVE-2020-37268MEDIUMCoq and Rocq Prover Print Assumptions Omits Unsafe Universe Checking Inlined Through Parameter InlineEPSS 0.1%CVE-2026-90955MEDIUMMISP CLI Shell Audit Logs Lose User Identity and CLI Marker After First Lazy Model LoadEPSS 0.1%CVE-2026-32803LOWDell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 conEPSS 0.1%