CWE-1059: Insufficient Technical Documentation
The product does not contain sufficient technical or engineering documentation (whether on paper or in electronic form) that contains descriptions of all the relevant software/hardware elements of the product, such as its usage, structure, architectural components, interfaces, design, implementation, configuration, operation, etc.
3 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-59084 — Apache Tomcat: EncryptInterceptor requirements not clearly documented
- CVE-2026-48035 — Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened
Recently published
- CVE-2026-48035 — Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened
- CVE-2026-59084 — Apache Tomcat: EncryptInterceptor requirements not clearly documented