
CVE-2026-40127 OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the C… https://www.cve.org/CVERecord?id=CVE-2026-40127
Post summary
OutSystems Lifetime has been disclosed with CVE-2026-40127, an authorization bypass via the ApplicationID parameter; no PoC, exploit, or patch information is provided.

