Main content

CVE-2026-40463
An Insufficient Role-based Access Control Vulnerability in WaveSuite

Public disclosure

31-08-2026

Last updated

31-08-2026

Vulnerability type

Improper Access Control

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

CVSS score

7.6

Description

WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser.

Affected products and versions

WaveSuite versions 25.6, 24.12, 24.6, 23.12 and 23.6.

Mitigation plan

Fixes have been provided in WaveSuite version 25.12FP1 and later releases.

Acknowledgements