CVE-2026-40127Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any application. This issue was fixed in OutSystems Lifetime version 11.28.2.3955

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-25: 2Technical Details · 2026-05-25: 205-25
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40127 OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the C… https://www.cve.org/CVERecord?id=CVE-2026-40127

    Post summary

    OutSystems Lifetime has been disclosed with CVE-2026-40127, an authorization bypass via the ApplicationID parameter; no PoC, exploit, or patch information is provided.

    00000236
    57.5K followersView on X
  • Israel@f1tym1
    Disclosure

    Vulnerability in Lifetime software https://ift.tt/rh7vpcW Authorization Bypass Through User-Controlled Key vulnerability (CVE-2026-40127) has been found in OutSystems Lifetime software. Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get…

    Post summary

    The post discloses CVE-2026-40127, an authorization bypass vulnerability in OutSystems Lifetime software, without providing exploit code, patch details, or evidence of active exploitation.

    0000065
    980 followersView on X

Explore more