CVE-2026-40464 PUBLISHED

A Stored Cross-Site Scripting (XSS) Vulnerability in Nokia NSP

Assigner: Nokia
Reserved: 13.04.2026 Published: 31.08.2026 Updated: 31.08.2026

NSP is vulnerable to a stored XSS due to insufficient validation or encoding of user-controlled input in a workflow application. An authenticated attacker with access to the workflow application could embed harmful code that runs when another user views the content.

Product Status

Vendor Nokia
Product NSP
Versions
  • Version 22.3 is affected
  • Version 22.6 is affected
  • Version 22.9 is affected
  • Version 22.11 is affected
  • Version 23.4 is affected
  • Version 23.8 is affected
  • Version 23.11 is affected
  • Version 24.4 is affected
  • Version 24.8 is affected
  • Version 24.11 is affected
  • Version 25.4 is affected
  • Version 25.8 is affected
  • Version 25.11 is affected
  • Version 24.11-SP15 is unaffected
  • Version 25.11-SP5 is unaffected
  • Version NSP 26.4 and later is unaffected

References