SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-40464

MEDIUM · CVSS 5.4 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows an authenticated attacker to exploit insufficient validation or encoding of user input in a workflow application, enabling them to inject malicious code that executes when other users access the affected content. This stored cross-site scripting (XSS) flaw poses a significant risk to user data and application integrity. Organizations utilizing this workflow application should prioritize remediation to protect against potential exploitation.

CVE
CVE-2026-40464
Severity
MEDIUM
CVSS
5.4
EPSS
0.13%

Original NVD Description

NSP is vulnerable to a stored XSS due to insufficient validation or encoding of user-controlled input in a workflow application. An authenticated attacker with access to the workflow application could embed harmful code that runs when another user views the content.