CVE-2026-40463: An Insufficient Role-based Access Control Vulnerability in WaveSuite
Published Aug 31, 2026
·Updated
WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser.
Affected Software
1 affected component
WaveSuite
Event History
Aug 31, 2026
CVE Published
via MITRE·06:32 AM
Data Sourced
via MITRE·06:32 AM
Description
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker must be authenticated as a low-privilege WaveSuite user. The issue does not describe exploitation by unauthenticated users.
2
How is the access control restriction bypassed?
The low-privilege user can directly request in a browser the URL of a CPB Log Files page that should be restricted to a higher-privilege role.