Unrated severityNVD Advisory· Published May 25, 2026
Authorization Bypass Through User-Controlled Key in OutSystems Lifetime
CVE-2026-40127
Description
OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any application.
This issue was fixed in OutSystems Lifetime version 11.28.2.3955
Affected products
1- Range: < 11.28.2.3955
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- cert.pl/en/posts/2026/05/CVE-2026-40126/mitrethird-party-advisory
- www.outsystems.com/downloads/ScreenDetailsmitreproduct
News mentions
0No linked articles in our index yet.