CVE-2026-40127
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
May 25, 2026
Vendor
unknown
Description
OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any application. This issue was fixed in OutSystems Lifetime version 11.28.2.3955