Report: Update: CVE-2026-40127 - Authorization Bypass Through User-Controlled Key in OutSystems Lifetime

Report: Update: CVE-2026-40127 - Authorization Bypass Through User-Controlled Key in OutSystems Lifetime

CVE ID :CVE-2026-40127 Published : 25 May 2026, 10:18 a.m. | 1 hour, 39 minutes ago Description :OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any application. This issue was fixed in OutSystems Lifetime version 11.28.2.3955 Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM