CVE-2026-40126Disclosure

LOWCVSS 4.8 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicious filename containing JavaScript code. The vulnerability exists in all locations where a file can be attached and prepared for upload to the server. This issue was fixed in OutSystems Service Center version 11.41.2

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-17: 2Technical Details · 2026-08-17: 208-17
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • ThreadLinqs@threadlinqs
    Disclosure

    CVE-2026-40126: DOM-based XSS in OutSystems Service Center. https://intel.threadlinqs.com/threat/TL-2026-2043 #ThreatIntel #CVE_2026_40126 https://t.co/eFKSKabwXC

    Post summary

    The tweet announces the CVE-2026-40126 DOM‑based XSS vulnerability in OutSystems Service Center and provides a link to threat‑intel information, but does not include a PoC, exploit, patch, or evidence of active exploitation.

    0000064
    133 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40126 DOM-based XSS in OutSystems Service Center via Malicious Filename Upload https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40126 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A new DOM‑based XSS vulnerability (CVE‑2026‑40126) in OutSystems Service Center triggered by malicious filename uploads has been disclosed, with no PoC, exploit, or patch information provided.

    00000123
    4.1K followersView on X

Explore more