CVE Database
/

CVE-2026-40127

Back to search

CVE-2026-40127

Published: May 25, 2026

Modified: May 26, 2026

PUBLISHED

Description

OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any application. This issue was fixed in OutSystems Lifetime version 11.28.2.3955

VendorProductVersions

OutSystems

Lifetime

affected
0 - < 11.28.2.3955

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now