ZeroHour

CVE-2026-40463

Broken access control in WaveSuite CPB Log Files exposes restricted pages

CVSS 3.1
7.6 high
EPSS
<1%p18
Published
()
Modified
AI analysis

WaveSuite contains an insufficient role-based access control flaw (CWE-284) in its CPB Log Files feature, where the application fails to enforce role restrictions when restricted pages are requested directly. An authenticated user holding only a low-privilege account can trigger it by simply entering the URL of a higher-privilege page in the browser; no user interaction beyond that request is required. Successful exploitation grants the attacker access to pages and their content that should be reserved for higher-privileged roles, and the CVSS 3.1 vector (C:H/I:L/A:L) indicates the impact is primarily to confidentiality, with limited integrity and availability impact. Any WaveSuite deployment that exposes the CPB Log Files feature and has low-privilege accounts is potentially affected; the exact affected version range is not specified in the available data. There is no evidence of active exploitation, no known public proof-of-concept, the issue is not in CISA KEV, and EPSS currently estimates only a 0.3% probability of exploitation within 30 days.

What to do: Apply the vendor's fixed WaveSuite release as soon as it is published, and monitor the vendor security advisory for the exact affected and fixed version details. As an interim mitigation, restrict direct URL access to the CPB Log Files pages for low-privilege roles (e.g., via reverse-proxy or web-server ACL rules), and review logs for low-privilege accounts that may have retrieved restricted log pages.

Affected
WaveSuite (CPB Log Files feature)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.