CWE-390Base

Detection of Error Condition Without Action

Draft in the CWE catalog · 20 CVEs mapped

20
CVEs mapped
6.6
Median CVSS
What it is

The product detects a specific error, but takes no actions to handle the error.

Recent examples
7.8cvss
CVE-2026-76642

CVE-2026-76642 - HIGH Severity Vulnerability

util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.

HIGHno explanation yet
0%
epss
5.3cvss
CVE-2026-59845

CVE-2026-59845 - MEDIUM Severity Vulnerability

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.

MEDIUMno explanation yet
0%
epss
9.1cvss
CVE-2026-53434

Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.

CRITICALno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-390
Abstraction
Base
Structure
Simple
Status
Draft
References (1)