CWE-778: Insufficient Logging
When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.
29 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-48967 — Life2000 ventilator and Service PC lack sufficient audit logging capabilities
- CVE-2026-32693 — Unauthorized access to Kubernetes secrets in Juju
- CVE-2026-76208 — phpMyFAQ 3.1.0 through 4.1.6 Authentication Bypass via LDAP
- CVE-2026-82863 — @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection
- CVE-2026-25598 — Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)
- CVE-2020-37268 — Coq and Rocq Prover Print Assumptions Omits Unsafe Universe Checking Inlined Through Parameter Inline
- CVE-2025-32967 — OpenEMR doesn't log password administration properly
- CVE-2026-3494 — MariaDB Server Audit Plugin Comment Handling Bypass
- CVE-2024-10863 — Client-side audit exclusion vulnerability
- CVE-2025-62307 — HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
- CVE-2026-22279 — Dell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An unauthenticated attac
- CVE-2025-66552 — Nextcloud Server admin_audit does not log all actions on files in groupfolders
- CVE-2024-24901 — Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with h
- CVE-2026-32803 — Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0
- CVE-2026-41709 — ESX insufficient logging vulnerability
- CVE-2026-9247 — Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissi
- CVE-2025-53498 — Lack of Audit Logging in AbuseFilter
- CVE-2025-2562 — Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated
Recently published
- CVE-2026-82863 — @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection
- CVE-2020-37268 — Coq and Rocq Prover Print Assumptions Omits Unsafe Universe Checking Inlined Through Parameter Inline
- CVE-2025-62307 — HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
- CVE-2026-76208 — phpMyFAQ 3.1.0 through 4.1.6 Authentication Bypass via LDAP
- CVE-2026-41709 — ESX insufficient logging vulnerability
- CVE-2026-9247 — Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissi
- CVE-2026-32803 — Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0
- CVE-2026-32693 — Unauthorized access to Kubernetes secrets in Juju
- CVE-2026-3494 — MariaDB Server Audit Plugin Comment Handling Bypass
- CVE-2026-25598 — Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)
- CVE-2026-22279 — Dell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An unauthenticated attac
- CVE-2025-66552 — Nextcloud Server admin_audit does not log all actions on files in groupfolders
- CVE-2025-53498 — Lack of Audit Logging in AbuseFilter
- CVE-2025-32967 — OpenEMR doesn't log password administration properly
- CVE-2025-2562 — Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated
- CVE-2024-10863 — Client-side audit exclusion vulnerability
- CVE-2024-48967 — Life2000 ventilator and Service PC lack sufficient audit logging capabilities
- CVE-2024-24901 — Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with h