CVE-2026-40126: DOM-based Cross-Site Scripting in OutSystems Service Center
OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicious filename containing JavaScript code. The vulnerability exists in all locations where a file can be attached and prepared for upload to the server.
This issue was fixed in OutSystems Service Center version 11.41.2
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OutSystems Service Centerto a version that resolves this vulnerability.Fixed in 11.41.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40126?
CVE-2026-40126 has a risk severity score of 52, indicating a moderate threat level.
What type of vulnerability is CVE-2026-40126?
CVE-2026-40126 is categorized as a DOM-based Cross-Site Scripting (XSS) vulnerability.
How can attackers exploit CVE-2026-40126?
Attackers can exploit CVE-2026-40126 by uploading a file with a malicious filename containing JavaScript code.
How do I fix CVE-2026-40126?
To mitigate CVE-2026-40126, ensure proper validation and sanitization of file attachments to prevent malicious script execution.
Which software is affected by CVE-2026-40126?
CVE-2026-40126 affects the OutSystems Service Center software.