Executive brief
NSP (Nokia Service Platform) is a network management system used by telecommunications and service providers. A vulnerability allows authenticated users to inject malicious code into workflow applications, which executes when other users access the affected content. This could lead to session hijacking, credential theft, or unauthorized changes to network configurations.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw caused by insufficient validation and encoding of user-controlled input in NSP's workflow application component. An authenticated attacker can inject malicious JavaScript or HTML into workflow data that persists in the application database. When other users view the contaminated content, the malicious code executes in their browser context with the same permissions as the authenticated user. The vulnerability requires authentication and user interaction (viewing the crafted content), limiting its immediate impact but enabling session hijacking or data exfiltration attacks. Nokia has published a security advisory with the CVE identifier.
Affected products
- Nokia NSP <UNKNOWN>
Timeline
- 2026-08-31: disclosed