Authorization Bypass Vulnerability in OutSystems Lifetime
CVE-2026-40127

5.3MEDIUM

Key Information:

Vendor

Outsystems

Status
Vendor
CVE Published:
25 May 2026

What is CVE-2026-40127?

OutSystems Lifetime is impacted by an authorization bypass vulnerability involving the ApplicationID parameter. This flaw enables any authenticated user to access the Change Log, which reveals actions performed by other users as well as the names of applications. Such unauthorized access could lead to exposure of sensitive information and operational risks within an OutSystems environment. The issue has been addressed in version 11.28.2.3955.

Affected Version(s)

Lifetime 0 < 11.28.2.3955

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zbigniew Piotrak (AFINE Team)
.