Stored XSS Vulnerability in Nokia's Workflow Application
CVE-2026-40464

Currently unrated

Key Information:

Vendor

Nokia

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-40464?

Nokia's workflow application contains a stored XSS vulnerability resulting from inadequate validation of user-supplied data. An authenticated attacker could exploit this flaw by embedding malicious scripts in the application. When another user accesses the compromised content, the harmful code executes, potentially compromising user data and security.

Affected Version(s)

NSP 22.3

NSP 22.6

NSP 22.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.