OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, canĀ read the Change Log containing actions performed by other users as well as application name of any application.
This issue was fixed in OutSystems Lifetime versionĀ 11.28.2.3955
CVSS
No CVSS.
References
Configurations
No configuration.
History
25 May 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-25 11:16
Updated : 2026-05-26 20:00
NVD link : CVE-2026-40127
Mitre link : CVE-2026-40127
CVE.ORG link : CVE-2026-40127
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
