CVE-2026-40127 PUBLISHED

Authorization Bypass Through User-Controlled Key in OutSystems Lifetime

Assigner: CERT-PL
Reserved: 09.04.2026 Published: 25.05.2026 Updated: 25.05.2026

OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any application.

This issue was fixed in OutSystems Lifetime version 11.28.2.3955

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor OutSystems
Product Lifetime
Versions Default: unknown
  • affected from 0 to 11.28.2.3955 (excl.)

Credits

  • Zbigniew Piotrak (AFINE Team) finder

References

Problem Types

  • CWE-639: Authorization Bypass Through User-Controlled Key CWE