2026-08-31 6:35CVE-2026-40464Nokia
PUBLISHED5.2

A Stored Cross-Site Scripting (XSS) Vulnerability in Nokia NSP

NSP is vulnerable to a stored XSS due to insufficient validation or encoding of user-controlled input in a workflow application. An authenticated attacker with access to the workflow application could embed harmful code that runs when another user views the content.

Affected products

Nokia

NSP

22.3 - AFFECTED

22.6 - AFFECTED

22.9 - AFFECTED

22.11 - AFFECTED

23.4 - AFFECTED

23.8 - AFFECTED

23.11 - AFFECTED

24.4 - AFFECTED

24.8 - AFFECTED

24.11 - AFFECTED

25.4 - AFFECTED

25.8 - AFFECTED

25.11 - AFFECTED

24.11-SP15 - UNAFFECTED

25.11-SP5 - UNAFFECTED

NSP 26.4 and later - UNAFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-40464
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-40464",
    "assignerOrgId": "b48c3b8f-639e-4c16-8725-497bc411dad0",
    "assignerShortName": "Nokia",
    "dateUpdated": "2026-08-31T06:35:32.425Z",
    "dateReserved": "2026-04-13T11:28:52.516Z",
    "datePublished": "2026-08-31T06:35:32.425Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "b48c3b8f-639e-4c16-8725-497bc411dad0",
        "shortName": "Nokia",
        "dateUpdated": "2026-08-31T06:35:32.425Z"
      },
      "title": "A Stored Cross-Site Scripting (XSS) Vulnerability in Nokia NSP",
      "descriptions": [
        {
          "lang": "en",
          "value": "NSP is vulnerable to a stored XSS due to insufficient validation or encoding of user-controlled input in a workflow application. An authenticated attacker with access to the workflow application could embed harmful code that runs when another user views the content."
        }
      ],
      "affected": [
        {
          "vendor": "Nokia",
          "product": "NSP",
          "versions": [
            {
              "version": "22.3",
              "status": "affected"
            },
            {
              "version": "22.6",
              "status": "affected"
            },
            {
              "version": "22.9",
              "status": "affected"
            },
            {
              "version": "22.11",
              "status": "affected"
            },
            {
              "version": "23.4",
              "status": "affected"
            },
            {
              "version": "23.8",
              "status": "affected"
            },
            {
              "version": "23.11",
              "status": "affected"
            },
            {
              "version": "24.4",
              "status": "affected"
            },
            {
              "version": "24.8",
              "status": "affected"
            },
            {
              "version": "24.11",
              "status": "affected"
            },
            {
              "version": "25.4",
              "status": "affected"
            },
            {
              "version": "25.8",
              "status": "affected"
            },
            {
              "version": "25.11",
              "status": "affected"
            },
            {
              "version": "24.11-SP15",
              "status": "unaffected"
            },
            {
              "version": "25.11-SP5",
              "status": "unaffected"
            },
            {
              "version": "NSP 26.4 and later",
              "status": "unaffected"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2026-40464/",
          "name": "Nokia Product Security Advisory"
        }
      ]
    }
  }
}