Insufficient Role-Based Access Control in WaveSuite by Nokia
CVE-2026-40463
Currently unrated
What is CVE-2026-40463?
WaveSuite by Nokia is vulnerable to an insufficient role-based access control flaw within the CPB Log Files feature. This vulnerability enables an authenticated low-privilege user to bypass restrictions by directly accessing URLs intended for higher-privilege roles, potentially exposing sensitive information and functionality not meant for their access level.
Affected Version(s)
WaveSuite 25.6
WaveSuite 24.12
WaveSuite 24.6