WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser.
PUBLISHED5.2
An Insufficient Role-based Access Control Vulnerability in WaveSuite
Affected products
Nokia
WaveSuite
25.6 - AFFECTED
24.12 - AFFECTED
24.6 - AFFECTED
23.6 - AFFECTED
25.12FP1 and later - UNAFFECTED
References
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-40463Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-40463",
"assignerOrgId": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"assignerShortName": "Nokia",
"dateUpdated": "2026-08-31T06:32:25.491Z",
"dateReserved": "2026-04-13T11:28:52.516Z",
"datePublished": "2026-08-31T06:32:25.491Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"shortName": "Nokia",
"dateUpdated": "2026-08-31T06:32:25.491Z"
},
"title": "An Insufficient Role-based Access Control Vulnerability in WaveSuite",
"descriptions": [
{
"lang": "en",
"value": "WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser."
}
],
"affected": [
{
"vendor": "Nokia",
"product": "WaveSuite",
"versions": [
{
"version": "25.6",
"status": "affected"
},
{
"version": "24.12",
"status": "affected"
},
{
"version": "24.6",
"status": "affected"
},
{
"version": "23.6",
"status": "affected"
},
{
"version": "25.12FP1 and later",
"status": "unaffected"
}
]
}
],
"references": [
{
"url": "https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2026-40463/",
"name": "Nokia Product Security Advisory"
}
]
}
}
}