Stored XSS Vulnerability in Nokia's Workflow Application
CVE-2026-40464
Currently unrated
What is CVE-2026-40464?
Nokia's workflow application contains a stored XSS vulnerability resulting from inadequate validation of user-supplied data. An authenticated attacker could exploit this flaw by embedding malicious scripts in the application. When another user accesses the compromised content, the harmful code executes, potentially compromising user data and security.
Affected Version(s)
NSP 22.3
NSP 22.6
NSP 22.9