CVE-2026-40463
—Broken access control in WaveSuite CPB Log Files exposes restricted pages
WaveSuite contains an insufficient role-based access control flaw (CWE-284) in its CPB Log Files feature, where the application fails to enforce role restrictions when restricted pages are requested directly. An authenticated user holding only a low-privilege account can trigger it by simply entering the URL of a higher-privilege page in the browser; no user interaction beyond that request is required. Successful exploitation grants the attacker access to pages and their content that should be reserved for higher-privileged roles, and the CVSS 3.1 vector (C:H/I:L/A:L) indicates the impact is primarily to confidentiality, with limited integrity and availability impact. Any WaveSuite deployment that exposes the CPB Log Files feature and has low-privilege accounts is potentially affected; the exact affected version range is not specified in the available data. There is no evidence of active exploitation, no known public proof-of-concept, the issue is not in CISA KEV, and EPSS currently estimates only a 0.3% probability of exploitation within 30 days.
What to do: Apply the vendor's fixed WaveSuite release as soon as it is published, and monitor the vendor security advisory for the exact affected and fixed version details. As an interim mitigation, restrict direct URL access to the CPB Log Files pages for low-privilege roles (e.g., via reverse-proxy or web-server ACL rules), and review logs for low-privilege accounts that may have retrieved restricted log pages.
| WaveSuite (CPB Log Files feature) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.