CVE-2026-40127

OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, canĀ read the Change Log containing actions performed by other users as well as application name of any application. This issue was fixed in OutSystems Lifetime versionĀ 11.28.2.3955
CVSS

No CVSS.

Configurations

No configuration.

History

25 May 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-25 11:16

Updated : 2026-05-26 20:00


NVD link : CVE-2026-40127

Mitre link : CVE-2026-40127

CVE.ORG link : CVE-2026-40127


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key