← Database

CVE-2026-40463

HIGH CVSS: 7.6 Published: 2026-08-31 Modified: 2026-08-31

Description

WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser.

Affected Platforms

Unknown

Weakness Type

CWE-284

References