NokiaCVE-2026-40464
Nokia NSP: cross-site scripting
Medium5.4CVE-2026-40464 · Published Aug 31, 2026 · updated Sep 3, 2026
NSP is vulnerable to a stored XSS due to insufficient validation or encoding of user-controlled input in a workflow application. An authenticated attacker with access to the workflow application could embed harmful code that runs when another user views the content.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| NSP Product | <= 22.3 | No fix yet |
| <= 22.6 | No fix yet | |
| <= 22.9 | No fix yet | |
| <= 22.11 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-79
More Nokia advisories
All Nokia| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 31 | Nokia NSP: open redirect | Medium5.3 | No fix yet |
| Aug 31 | Nokia WaveSuite: improper access control | High7.6 | No fix yet |