CVE-2026-40127: Authorization Bypass Through User-Controlled Key in OutSystems Lifetime
OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any application.
This issue was fixed in OutSystems Lifetime version 11.28.2.3955
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OutSystems Lifetimeto a version that resolves this vulnerability.Fixed in 11.28.2.3955
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40127?
The severity of CVE-2026-40127 is rated as medium with a CVSS score of 5.3.
How does CVE-2026-40127 affect users?
CVE-2026-40127 allows any authenticated user to bypass authorization and read the Change Log of other users.
What software is impacted by CVE-2026-40127?
CVE-2026-40127 affects the OutSystems Lifetime application.
How can I mitigate the risk associated with CVE-2026-40127?
To mitigate the risk of CVE-2026-40127, ensure you apply the security patches provided by OutSystems.
What type of vulnerability is CVE-2026-40127?
CVE-2026-40127 is categorized as an Authorization Bypass vulnerability through a user-controlled key.