| CVE ID | CVE-2026-40127 |
| Publication date | 25 May 2026 |
| Vendor | OutSystems |
| Product | Lifetime |
| Vulnerable versions | All before 11.28.2.3955 |
| Vulnerability type (CWE) | Authorization Bypass Through User-Controlled Key (CWE-639) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in OutSystems Lifetime software and participated in coordination of its disclosure.
The vulnerability CVE-2026-40127: OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user can read the Change Log containing actions performed by other users as well as application name of any application.
This issue was fixed in OutSystems Lifetime version 11.28.2.3955
Credits
We thank Zbigniew Piotrak (AFINE Team) for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.