NSP is vulnerable to a stored XSS due to insufficient validation or encoding of user-controlled input in a workflow application. An authenticated attacker with access to the workflow application could embed harmful code that runs when another user views the content.
PUBLISHED5.2
A Stored Cross-Site Scripting (XSS) Vulnerability in Nokia NSP
Affected products
Nokia
NSP
22.3 - AFFECTED
22.6 - AFFECTED
22.9 - AFFECTED
22.11 - AFFECTED
23.4 - AFFECTED
23.8 - AFFECTED
23.11 - AFFECTED
24.4 - AFFECTED
24.8 - AFFECTED
24.11 - AFFECTED
25.4 - AFFECTED
25.8 - AFFECTED
25.11 - AFFECTED
24.11-SP15 - UNAFFECTED
25.11-SP5 - UNAFFECTED
NSP 26.4 and later - UNAFFECTED
References
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-40464Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-40464",
"assignerOrgId": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"assignerShortName": "Nokia",
"dateUpdated": "2026-08-31T06:35:32.425Z",
"dateReserved": "2026-04-13T11:28:52.516Z",
"datePublished": "2026-08-31T06:35:32.425Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"shortName": "Nokia",
"dateUpdated": "2026-08-31T06:35:32.425Z"
},
"title": "A Stored Cross-Site Scripting (XSS) Vulnerability in Nokia NSP",
"descriptions": [
{
"lang": "en",
"value": "NSP is vulnerable to a stored XSS due to insufficient validation or encoding of user-controlled input in a workflow application. An authenticated attacker with access to the workflow application could embed harmful code that runs when another user views the content."
}
],
"affected": [
{
"vendor": "Nokia",
"product": "NSP",
"versions": [
{
"version": "22.3",
"status": "affected"
},
{
"version": "22.6",
"status": "affected"
},
{
"version": "22.9",
"status": "affected"
},
{
"version": "22.11",
"status": "affected"
},
{
"version": "23.4",
"status": "affected"
},
{
"version": "23.8",
"status": "affected"
},
{
"version": "23.11",
"status": "affected"
},
{
"version": "24.4",
"status": "affected"
},
{
"version": "24.8",
"status": "affected"
},
{
"version": "24.11",
"status": "affected"
},
{
"version": "25.4",
"status": "affected"
},
{
"version": "25.8",
"status": "affected"
},
{
"version": "25.11",
"status": "affected"
},
{
"version": "24.11-SP15",
"status": "unaffected"
},
{
"version": "25.11-SP5",
"status": "unaffected"
},
{
"version": "NSP 26.4 and later",
"status": "unaffected"
}
]
}
],
"references": [
{
"url": "https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2026-40464/",
"name": "Nokia Product Security Advisory"
}
]
}
}
}