Junglewise Threat Intelligence

CVE-2026-40463: WaveSuite insufficient role-based access control in CPB Log Files

CVE-2026-40463 · Severity: high · CVSS 7.6 · Published 2026-08-31

Vendors: Nokia.

Executive brief

WaveSuite is a system management platform used to administer network infrastructure and services. A flaw in the CPB Log Files feature allows low-privilege users to bypass access controls and view restricted pages intended only for administrators. An attacker with basic user credentials can directly request sensitive log pages in a browser to gain unauthorized visibility into system operations and potentially sensitive information.

Technical details

The vulnerability is a broken access control flaw in the CPB Log Files feature of WaveSuite. An authenticated low-privilege user can bypass role-based access controls by directly requesting URLs that should be restricted to higher-privilege roles, without additional authentication or checks. The vulnerability allows an attacker to enumerate and access log files and administrative pages not intended for their privilege level. This is a horizontal privilege escalation triggered purely by URL manipulation, requiring only valid (low-level) authentication and network access to the WaveSuite interface. Patch availability was not confirmed from the provided sources.

Affected products

  • Nokia WaveSuite

Timeline

  • 2026-08-31: disclosed

References