CWE-778— Insufficient Logging
When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.— MITRE CWE catalog
37 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-778page 1 of 1
- CVE-2024-48967CRITICALCVSS 10.0EG 10.02024-11-14
The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent forensic examination. An attacker with access to the ventilator and/or the Service PC could, without d…
- CVE-2026-32693HIGHCVSS 8.8EG 8.82026-03-18
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set"…
- CVE-2026-76208HIGHCVSS 8.2EG 8.22026-08-19
phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful LDAP bind the code calls User::setStatus('active') unconditionally, which o…
- CVE-2025-52644HIGHCVSS 8.2EG 8.22026-03-16
HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could potentially impact monitoring, accounta…
- CVE-2026-22279HIGHCVSS 7.5EG 7.52026-01-22
Dell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information tampering.
- CVE-2021-43419HIGHCVSS 7.5EG 7.52023-11-07
An Information Disclosure vulnerability exists in Opay Mobile application 1.5.1.26 and maybe be higher in the logcat app.
- CVE-2019-7613HIGHCVSS 7.5EG 7.52019-03-25
Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event.
- CVE-2022-30305HIGHCVSS 3.7EG 7.52022-12-06
An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2…
- CVE-2026-66816MEDIUMCVSS 6.5EG 6.52026-09-08
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
- CVE-2019-19277MEDIUMCVSS 6.5EG 6.52020-03-10
A vulnerability has been identified in SIPORT MP (All versions < 3.1.4). Vulnerable versions of the device allow the creation of special accounts ("service users") with administrative privileges that could enable a remote authenticated att…
- CVE-2020-37268MEDIUMCVSS 6.3EG 6.32026-08-24
Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in a module type. Applying a functor inlines the body of the parameter, …
- CVE-2025-62307MEDIUMCVSS 5.4EG 5.42026-08-20
HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing.
- CVE-2025-32967MEDIUMCVSS 5.4EG 5.42025-05-23
OpenEMR is a free and open source electronic health records and medical practice management application. A logging oversight in versions prior to 7.0.3.4 allows password change events to go unrecorded on the client-side log viewer, prevent…
- CVE-2025-2562MEDIUMCVSS 5.4EG 5.42025-03-26
Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password without generating a corresponding log event, via the use of the autotyping functionality…
- CVE-2026-105243MEDIUMCVSS 5.3EG 5.32026-10-06
Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then s…
- CVE-2026-91859MEDIUMCVSS 5.3EG 5.32026-09-15
Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering runs the application startup path a second time. As a resu…
- CVE-2026-25598MEDIUMCVSS 5.3EG 5.32026-02-09
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security vulnerability has been identified in the Harden-Runner GitHub Action (Community Tier) that allows outbound network conne…
- CVE-2025-53498MEDIUMCVSS 5.3EG 5.32025-07-07
Insufficient Logging vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Data Leakage Attacks.This issue affects Mediawiki - AbuseFilter Extension: from 1.43.X before 1.43.2.
- CVE-2023-1995MEDIUMCVSS 5.3EG 5.32023-08-29
Insufficient Logging vulnerability in Hitachi HiRDB Server, HiRDB Server With Addtional Function, HiRDB Structured Data Access Facility.This issue affects HiRDB Server: before 09-60-39, before 09-65-23, before 09-66-17, before 10-01-10…
- CVE-2026-92002MEDIUMCVSS 5.1EG 5.12026-09-15
Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still recording failed authentication activity. However, User->setupRedis() returns false …
- CVE-2024-10863MEDIUMCVSS 5.1EG 5.12024-11-22
: Insufficient Logging vulnerability in OpenText Secure Content Manager on Windows allows Audit Log Manipulation.This issue affects Secure Content Manager: from 10.1 before <24.4. End-users can potentially exploit the vulnerability to e…
- CVE-2026-90955MEDIUMCVSS 4.6EG 4.62026-09-14
Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID. However, the legacy SysLogLoga…
- CVE-2026-18161MEDIUMCVSS 4.3EG 4.32026-09-22
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a client-supplied HTTP header.
- CVE-2026-29812MEDIUMCVSS 4.3EG 4.32026-09-13
CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.
- CVE-2026-3494MEDIUMCVSS 4.3EG 4.32026-03-03
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixe…
- CVE-2025-66552MEDIUMCVSS 4.3EG 4.32025-12-05
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files an…
- CVE-2024-2291MEDIUMCVSS 4.3EG 4.32024-03-20
In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered. An authenticated user could manipulate a request to…
- CVE-2022-25783MEDIUMCVSS 4.3EG 4.32022-05-04
Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. This issue affects: Secomea GateManager versions prior to 9.7.
- CVE-2021-33689MEDIUMCVSS 4.3EG 4.32021-07-14
When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrity is impacted.
- CVE-2019-19295MEDIUMCVSS 4.3EG 4.32020-03-10
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) does not enforce logging of security-relevant activities in its XML-based communication protocol as provided by def…
- CVE-2026-82863LOWCVSS 3.3EG 3.32026-08-31
@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially…
- CVE-2026-32803LOWCVSS 3.3EG 3.32026-05-08
Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 contains an Insufficient Logging vulnerability. A low privileged attacker with local access could pote…
- CVE-2021-32680LOWCVSS 3.3EG 3.32021-07-12
Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a share expiration date.…
- CVE-2024-24901LOWCVSS 3.0EG 3.02024-03-04
Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, causing audit messages lost and not recorded for a specifi…
- CVE-2026-41709LOWCVSS 2.7EG 2.72026-07-30
VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.
- CVE-2026-9247LOWCVSS 2.4EG 2.42026-05-26
Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the unseal notification to administrators via a crafted export request.…
- CVE-2022-31120LOWCVSS 2.1EG 2.12022-08-04
Nextcloud server is an open source personal cloud solution. The audit log is used to get a full trail of the actions which has been incompletely populated. In affected versions federated share events were not properly logged which would al…
Map vulnerabilities like CWE-778 to your infrastructure
EchelonGraph correlates every CVE — across CWE-778 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →