CWE-1059Class

Insufficient Technical Documentation

Incomplete in the CWE catalog · 3 CVEs mapped

3
CVEs mapped
9.1
Median CVSS
What it is

The product does not contain sufficient

technical or engineering documentation (whether on paper or

in electronic form) that contains descriptions of all the

relevant software/hardware elements of the product, such as

its usage, structure, architectural components, interfaces, design, implementation,

configuration, operation, etc.

Recent examples
7.1cvss
CVE-2026-48035

Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal — while believing the startup-hardened tier guaranteed tamper-resistance. Sandbox-tier deployments had no audit immutability at all (defects 1 and 3 compounded). This issue has been patched in version 1.4.0.

HIGHno explanation yet
0%
epss
9.1cvss
CVE-2026-59084

Apache Tomcat: EncryptInterceptor requirements not clearly documented

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

CRITICALno explanation yet
1%
epss
9.8cvss
CVE-2022-3270

Incomplete Documentation of remote functions in FESTO products.

🚨 An undocumented protocol in Festo products could let attackers waltz in undetected, jeopardizing your entire system! 🔥 Think of it like a secret door in a building that only a few know about — if someone finds it and sneaks in, they can rummage through everything without anyone noticing! This vulnerability allows attackers to exploit that hidden entry point, leading to chaos inside your digital fortress. An attacker could completely compromise confidentiality, integrity, and availability. In simpler terms, they could read, alter, or delete any data, leaving you with a shattered security landscape and no idea how it happened. Imagine your sensitive information exposed and your systems brought to their knees — absolutely devastating!

CRITICAL
1%
epss
The record
Technical detail
CWE ID
CWE-1059
Abstraction
Class
Structure
Simple
Status
Incomplete
References (2)