CVE-2026-40464: A Stored Cross-Site Scripting (XSS) Vulnerability in Nokia NSP
Published Aug 31, 2026
·Updated
NSP is vulnerable to a stored XSS due to insufficient validation or encoding of user-controlled input in a workflow application. An authenticated attacker with access to the workflow application could embed harmful code that runs when another user views the content.
Affected Software
1 affected component
Nokia NSP
Event History
May 12, 2026
News Published
via Dark Reading·09:03 PM
May 13, 2026
News Published
via Dark Reading·12:06 PM
Aug 31, 2026
CVE Published
via MITRE·06:35 AM
Data Sourced
via MITRE·06:35 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires an authenticated attacker who has access to the NSP workflow application. The attacker must be able to submit user-controlled content through that application.
2
Who is exposed to the injected code?
Other users are exposed when they view workflow content containing the attacker’s stored payload. The issue is therefore relevant where workflow content is shared or reviewed by other users.