Description
WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser.
Published: 2026-08-31
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to restricted pages
Action: Mitigate
AI Analysis

Impact

The vulnerability arises from an insufficient role‑based access control in the CPB Log Files feature of Nokia WaveSuite. An authenticated user with a low‑privilege role can bypass restrictions by directly entering the URL of a page that is intended for higher‑privilege roles. This flaw enables the attacker to view or download content, logs, or other sensitive information that should be protected, potentially exposing confidential operational data.

Affected Systems

Nokia WaveSuite is the affected product. No specific software or firmware versions are listed in the advisory, indicating that all current releases may be susceptible until a patch is released. The flaw specifically impacts the CPB Log Files feature used for viewing logs, but other restricted pages accessed through the same path are also vulnerable.

Risk and Exploitability

The CVSS score is 7.6 and the EPSS score is < 1%, but the flaw is known to allow privileged data exposure after authentication. Because the vulnerability requires a valid account, the attack vector is limited to authenticated users, yet it can still be exploited internally by any low‑privilege user. The lack of a KEV listing suggests no public exploits yet, but administrators should treat it as a moderate‑to‑high risk until a vendor fix becomes available.

Generated by OpenCVE AI on August 31, 2026 at 20:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Implement strict role checks for the CPB Log Files feature, ensuring only authorized roles can access the corresponding URLs.
  • Disallow low‑privilege users from accessing URLs that return restricted content by configuring firewall rules or web server access controls.
  • Apply any WaveSuite security updates released by Nokia as soon as they become available.
  • Monitor web server logs for attempts to request restricted URLs by unauthorized users.

Generated by OpenCVE AI on August 31, 2026 at 20:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Nokia
Nokia wavesuite Noc
Vendors & Products Nokia
Nokia wavesuite Noc

Mon, 31 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Mon, 31 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}


Mon, 31 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Mon, 31 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser.
Title An Insufficient Role-based Access Control Vulnerability in WaveSuite
References

Subscriptions

Nokia Wavesuite Noc
cve-icon MITRE

Status: PUBLISHED

Assigner: Nokia

Published:

Updated: 2026-08-31T15:36:24.517Z

Reserved: 2026-04-13T11:28:52.516Z

Link: CVE-2026-40463

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-31T07:17:42.610

Modified: 2026-09-03T18:12:39.113

Link: CVE-2026-40463

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T21:15:05Z

Weaknesses