DOM-based XSS Vulnerability in OutSystems Service Center
CVE-2026-40126

4.8MEDIUM

Key Information:

Vendor

Outsystems

Vendor
CVE Published:
17 August 2026

What is CVE-2026-40126?

OutSystems Service Center suffers from a vulnerability that allows low-privileged attackers to execute a DOM-based Cross-Site Scripting (XSS) attack. This exploit is initiated through the upload of a file with a crafted filename containing malicious JavaScript code. The risk exists in all areas where files can be attached and sent to the server, which leaves a significant gap in security protocol. Users are urged to update to Service Center version 11.41.2 or later to mitigate this issue.

Affected Version(s)

Service Center 0 < 11.41.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zbigniew Piotrak (AFINE Team)
.