Falhas do tipo CWE-778

36 resultados

Registros insuficientes em log

Ocorre quando a aplicação não registra eventos críticos de segurança (tentativas de acesso, erros de autenticação, operações sensíveis) com detalhes suficientes. Sem logs adequados, é impossível detectar ataques em tempo real, investigar incidentes ou cumprir conformidade, deixando a segurança cega.

Exemplo

Um sistema que autentica usuários mas não registra tentativas falhadas de login, deixando ataques de força bruta passarem desapercebidos. Ou uma API que modifica dados críticos sem logar quem fez a mudança, impossibilitando rastreabilidade.

Como mitigar

Implemente logs estruturados e centralizados para eventos sensíveis (autenticação, autorização, mudanças de dados, erros críticos) com timestamp, identificação do usuário/origem e contexto. Configure alertas para padrões anormais e garanta retenção e proteção dos logs contra manipulação.

CVE-2026-76208HIGHphpMyFAQ 3.1.0 through 4.1.6 Authentication Bypass via LDAPEPSS 0.3%CVE-2026-91859MEDIUMMISP Access Log Entry Overwritten by Error Controller's Second beforeFilter PassEPSS 0.3%CVE-2025-32967MEDIUMOpenEMR doesn't log password administration properlyEPSS 0.3%CVE-2026-3494MEDIUMMariaDB Server Audit Plugin Comment Handling BypassEPSS 0.3%CVE-2026-22279MEDIUMDell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An unauthenticated attacker with remote acceEPSS 0.3%CVE-2025-53498MEDIUMLack of Audit Logging in AbuseFilterEPSS 0.2%CVE-2026-9247LOWInsufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealEPSS 0.2%CVE-2026-29812MEDIUMCyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.EPSS 0.2%CVE-2025-62307MEDIUMHCL IntelliOps Event Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2026-82863HIGH@hulumi/baseline before 1.3.2 CloudTrail Selector Tampering DetectionEPSS 0.1%CVE-2024-24901LOWDell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with high privileges couldEPSS 0.1%CVE-2025-52644MEDIUMHCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged.EPSS 0.1%CVE-2020-37268MEDIUMCoq and Rocq Prover Print Assumptions Omits Unsafe Universe Checking Inlined Through Parameter InlineEPSS 0.1%CVE-2026-90955MEDIUMMISP CLI Shell Audit Logs Lose User Identity and CLI Marker After First Lazy Model LoadEPSS 0.1%CVE-2026-32803LOWDell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 conEPSS 0.1%CVE-2026-18161MEDIUMIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS