The CVE-2026-40464 record describes a stored XSS vulnerability in NSP workflow applications due to insufficient validation or encoding of user-controlled input. An authenticated attacker with access to the workflow application could embed harmful code that runs when another user views the content. Administrators and users of NSP workflow applications should verify their configurations and take defensive a [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T07:17:42.610Z and has not been modified since then. WaveSuite's CPB Log Files feature has an insufficient role-based access control vulnerability. An authenticated low-privilege user can load pages restricted to higher-privilege roles by directly requesting the corresponding URL in the browser. T [truncated]
Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacker to retrieve confidential information beyond their assigned privileges. This vulnerability affects users with access to the API, particularly those managing Nokia MantaRay Nm deployments. The vulnerability has a CVSS score of 6 [truncated]
Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to upload malicious files onto the system. This vulnerability has a high impact on users of Nokia MantaRay NM, as it could lead to unauthorized file uploads and potential system compromise. Users should review and apply necessary [truncated]
CVE-2025-9912 is a local privilege escalation vulnerability in Nokia SR Linux. An authenticated user may exploit this vulnerability to execute arbitrary commands with superuser privilege.
CVE-2025-10262 is a local privilege escalation vulnerability in Nokia SR Linux due to unsanitized format validation. An authenticated user could exploit this to execute arbitrary commands with superuser privileges.