Bastion Security

Nokia WS-NOC and NSP Vulnerabilities

During a security engagement, Steve Nyan Lin discovered numerous vulnerabilities within WS-NOC and NSP which could lead to a low-privileged user accessing administrative functionalities, cross-site scripting and open redirection.
Talk to an expert

During a security engagement, Steve Nyan Lin discovered numerous vulnerabilities within WS-NOC and NSP which could lead to a low-privileged user accessing administrative functionalities, cross-site scripting and open redirection.

Vulnerability: WS-NOC InsufficientRole-Based Access Controls (CVE-2026-40463)

This affects WS-NOC version 24.12.0-5295250526-FP1-Sand 24.12.0-5674250814-P2. There were insufficient access controls for the viewer user which could access functionalities limited to operators and above. For instance, a viewer user was able to access Commissioning and Power Balance(CPB) logs, import fiber routes and make changes to the network element password.

Vulnerability: NSP Stored Cross-SiteScripting (CVE-2026-40464)

This affects NSP Version:25.4.0-rel.568-SP2. The ReadME field of the Workflows allowed executionof JavaScript payloads due to insufficient input sanitization.

Vulnerability: NSP Open Redirect (CVE-2026-40465)

This affects NSP Version:25.4.0-rel.568-SP2. The login functionality in the NSP application isvulnerable to an open redirect via the state parameter. This could leadto an attacker redirecting unsuspecting users to malicious websites and performfurther attacks to obtain their credentials, such as phishing.

September 14, 2026

Introduction:

The WaveSuite Network Operations Center(WS-NOC) from Nokia, is a dedicated optical management product that can run standalone or as an NSP component, and it centralises connection, fault, and performance management for Nokia's optical portfolio in a single interface. Together, they give operators unified visibility and control across packet and optical network domains. Nokia's Network Services Platform (NSP) is a distributed, modular management suite developed by Nokia that unifies service automation and network optimization across IP, MPLS, optical, and microwave technologies using intent-based networking.

This post outlines the technical details ofthe vulnerability, how it can be exploited, and the potential impact on users. At the time of writing, Nokia has not released a patch for this issue or anyrecommended mitigation steps.

Vulnerability: WS-NOC Insufficient Role-Based Access Controls (CVE-2026-40463)

This affects WS-NOC version 24.12.0-5295250526-FP1-Sand 24.12.0-5674250814-P2. There were insufficient access controls for the viewer user which could access functionalities limited to operators and above. For instance, a viewer user was able to access Commissioning and Power Balance(CPB) logs, import fiber routes and make changes to the network element password.

Note the sectest3 user being aviewer:

(CVE-2026-40463) - WS-NOC Dashboard view

There are no options in the hamburger menu to view CPB logs, import fiber routes or make changes to the network element password:

However, it was possible to browse to the end points directly to access those functionalities:

Accessing CPB logs as viewer:

Accessing Fiber routes as viewer:

Accessing network element password change function as viewer:

As a viewer, it was possible to change passwords for Network Elements or view Fiber Routes. This could lead to service disruptions or information disclosure about internal network routes.

Vulnerability: NSP Stored Cross-SiteScripting (CVE-2026-40464)

This affects NSP Version:25.4.0-rel.568-SP2. The ReadME field of the Workflows allowed executionof JavaScript payloads due to insufficient input sanitization.

The workflow function can be created/editedby operators or administrators.

To reproduce this issue:

  1. Login as an operator or administrator.
  2. Click on the hamburger menu-> Workflows -> + Workflow.
  3. Enter valid YAML content and click on ReadMe.
  4.  Insert the following payload and click on Create.
    <a href=javascript:alert(document.domain)>
  5. Execute the workflow and observe the XSS payload being triggered.

This could allow an attacker to target administrator accounts. While the HttpOnly flag on the session cookie prevents direct cookie theft via JavaScript, the vulnerability can still be leveraged to coerce a victim administrator into unknowingly performing sensitive actions in their authenticated session, such as creating a new administrator account, changing their password, or modifying system configuration.

Screenshots:

The payload being triggered after inserting it into the README field:

<ahref=javascript:alert(document.domain)>

Vulnerability: NSP Open Redirect (CVE-2026-40465)

This affects NSP Version:25.4.0-rel.568-SP2. The login functionality in the NSP application isvulnerable to an open redirect via the state parameter. This could leadto an attacker redirecting unsuspecting users to malicious websites and perform further attacks to obtain their credentials, such as phishing.

To reproduce this issue:

  1. Navigate to the NSP login url.The vulnerable client is using Openid-connect and looks as follows:
    https://<base-URL>/auth/realms/Nokia/protocol/openid-connect/auth/client_id=NSP&redirect_uri=https:%3A%2F%<bas-URL>%3A443%2Foauth2&response_type=code&scope=openid+profile+email+roles+membership&
    state=12345--https:%3A%2F%2Fbastionsecurity.co.nz
  2. After modifying the state parameter, login as any user and observe successful redirection to the specified URL.

Recommendation:

Monitor the Nokia website for official patch availability and remediation guidance.

Implement IP-based access control lists to restrict access to the WS-NOC and NSP management interfaces.

Disclosure Timeline:

February 5th, 2026: Issues reported to the Nokia Security Team (PSIRT)

February 5th, 2026: Issues acknowledged

August 31st, 2026: CVEs assigned

September 3rd, 2026: Advisory Live


Service Development Manager
Government Agency
"Great service, clear, detailed and precise information on what our vulnerabilities were and what needs addressing. Couldn't have been easier to deal with and very professional."
Expert methods

We have the tools to pinpoint risks

Whether it’s hidden vulnerabilities or patterns you might miss, we help you stay one step ahead and make confident, informed decisions. Understand how our services can help your business uncover critical risks

Talk to an expert
Employee Cyber Training & Awareness
Your people are your first line of defence. Our cyber training builds awareness and sharpens their instincts.
Advisory
When clarity is critical and stakes are high, our advisory services deliver strategic, executive-level security expertise that empowers decision-making.