VORANT. Threat Intelligence Sign in Get the full feed

OutSystems Lifetime patches authorization bypass flaw

low vulnerability technology

A CERT Polska-coordinated vulnerability in OutSystems Lifetime let any authenticated user view other users' Change Log data via a manipulated ApplicationID parameter.

CERT Polska coordinated the disclosure of CVE-2026-40127, an Authorization Bypass Through User-Controlled Key vulnerability affecting OutSystems Lifetime. The flaw resides in the ApplicationID parameter, which any authenticated user could manipulate to access the Change Log of applications they are not authorized to view, exposing action histories performed by other users as well as application names.

The vulnerability was responsibly reported by Zbigniew Piotrak of the AFINE Team and has since been remediated by OutSystems in Lifetime version 11.28.2.3955. There is no indication of active exploitation; this is a coordinated disclosure with a patch already available. Organizations running OutSystems Lifetime should update to the fixed version to prevent unauthorized users from enumerating application metadata and audit log details.

Mentioned in this report

Vulnerabilities CVE-2026-40127

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-40127

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free