CVE-2026-40463 PUBLISHED

An Insufficient Role-based Access Control Vulnerability in WaveSuite

Assigner: Nokia
Reserved: 13.04.2026 Published: 31.08.2026 Updated: 31.08.2026

WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser.

Product Status

Vendor Nokia
Product WaveSuite
Versions
  • Version 25.6 is affected
  • Version 24.12 is affected
  • Version 24.6 is affected
  • Version 23.6 is affected
  • Version 25.12FP1 and later is unaffected

References