{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-40463","assignerOrgId":"b48c3b8f-639e-4c16-8725-497bc411dad0","state":"PUBLISHED","assignerShortName":"Nokia","dateReserved":"2026-04-13T11:28:52.516Z","datePublished":"2026-08-31T06:32:25.491Z","dateUpdated":"2026-08-31T15:36:24.517Z"},"containers":{"cna":{"title":"An Insufficient Role-based Access Control Vulnerability in WaveSuite","descriptions":[{"lang":"en","value":"WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser."}],"affected":[{"vendor":"Nokia","product":"WaveSuite","versions":[{"version":"25.6","status":"affected"},{"version":"24.12","status":"affected"},{"version":"24.6","status":"affected"},{"version":"23.6","status":"affected"},{"version":"25.12FP1 and later","status":"unaffected"}]}],"references":[{"url":"https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2026-40463/","name":"Nokia Product Security Advisory"}],"providerMetadata":{"orgId":"b48c3b8f-639e-4c16-8725-497bc411dad0","shortName":"Nokia","dateUpdated":"2026-08-31T06:32:25.491Z"},"x_generator":{"engine":"cveClient/1.0.15"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-284","lang":"en","description":"CWE-284 Improper Access Control"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.6,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","integrityImpact":"LOW","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"LOW","privilegesRequired":"LOW","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-08-31T15:36:13.476760Z","id":"CVE-2026-40463","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-31T15:36:24.517Z"}}]}}