CVE-2026-40463
7.6Nokia · WaveSuite
Nokia WaveSuite contains a broken access control vulnerability in the CPB Log Files feature, allowing low-privileged users to access restricted administrative pages.
Executive summary
A high-severity access control flaw in Nokia WaveSuite allows authenticated low-privilege users to bypass authorization and access restricted system pages.
Vulnerability
This is an insufficient role-based access control vulnerability (CWE-285) within the CPB Log Files feature. It allows any authenticated low-privileged user to access sensitive administrative endpoints simply by navigating directly to the restricted URL.
Business impact
The ability for low-privileged users to access restricted pages poses a significant risk of unauthorized information disclosure and potential privilege escalation. With a CVSS score of 7.6, this vulnerability is classified as high severity, as it undermines the core security model of the application and could allow attackers to gain visibility into sensitive logs or internal configurations.
Remediation
Immediate Action: Upgrade Nokia WaveSuite to version 25.12FP1 or any subsequent release, as these versions contain the necessary security fixes.
Proactive Monitoring: Review web server and application access logs for unexpected requests to administrative URL paths originating from low-privileged user accounts.
Compensating Controls: Implement strict URL-level access control filters at the Web Application Firewall (WAF) or reverse proxy level to block unauthorized access to sensitive administrative endpoints until the patch can be deployed.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the ease with which this vulnerability can be exploited by malicious insiders or compromised low-privilege accounts, organizations using Nokia WaveSuite must prioritize the update to version 25.12FP1 or higher. Failure to apply this patch leaves the system susceptible to unauthorized data access and potential administrative compromise.