{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-40127", "assignerOrgId": "4bb8329e-dd38-46c1-aafb-9bf32bcb93c6", "state": "PUBLISHED", "assignerShortName": "CERT-PL", "dateReserved": "2026-04-09T10:15:00.973Z", "datePublished": "2026-05-25T10:18:05.904Z", "dateUpdated": "2026-08-11T06:30:21.209Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "4bb8329e-dd38-46c1-aafb-9bf32bcb93c6", "shortName": "CERT-PL", "dateUpdated": "2026-08-11T06:30:21.209Z" }, "title": "Authorization Bypass Through User-Controlled Key in OutSystems Lifetime", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-639", "description": "CWE-639: Authorization Bypass Through User-Controlled Key", "type": "CWE" } ] } ], "affected": [ { "vendor": "OutSystems", "product": "Lifetime", "versions": [ { "status": "affected", "version": "0", "lessThan": "11.28.2.3955", "versionType": "semver" } ], "defaultStatus": "unknown" } ], "descriptions": [ { "lang": "en", "value": "OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, canĀ read the Change Log containing actions performed by other users as well as application name of any application.\n\nThis issue was fixed in OutSystems Lifetime versionĀ 11.28.2.3955", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any application.

This issue was fixed in OutSystems Lifetime version 11.28.2.3955
" } ] } ], "references": [ { "url": "https://cert.pl/en/posts/2026/05/CVE-2026-40126/", "tags": [ "third-party-advisory" ] }, { "url": "https://www.outsystems.com/downloads/ScreenDetails?ReleaseId=22953&MajorVersion=11&ComponentName=LifeTime", "tags": [ "product" ] }, { "url": "https://success.outsystems.com/support/security/vulnerabilities/vulnerability_rpm_6441/", "tags": [ "vendor-advisory" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "LOW", "subConfidentialityImpact": "NONE", "vulnIntegrityImpact": "NONE", "subIntegrityImpact": "NONE", "vulnAvailabilityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "MEDIUM", "baseScore": 5.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" } } ], "credits": [ { "lang": "en", "value": "Zbigniew Piotrak (AFINE Team)", "type": "finder" } ], "source": { "discovery": "EXTERNAL" }, "x_generator": { "engine": "Vulnogram 0.2.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-05-26T15:11:49.294978Z", "id": "CVE-2026-40127", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-05-26T15:20:07.870Z" } } ] } }