# OutSystems Lifetime patches authorization bypass flaw

Published: 2026-05-25 · Severity: low · Sectors: technology
Canonical: https://vorant.io/reports/1c826b00-1458-5b8e-9bd2-f601a07f59d6/outsystems-lifetime-patches-authorization-bypass-flaw

> A CERT Polska-coordinated vulnerability in OutSystems Lifetime let any authenticated user view other users' Change Log data via a manipulated ApplicationID parameter.

CERT Polska coordinated the disclosure of CVE-2026-40127, an Authorization Bypass Through User-Controlled Key vulnerability affecting OutSystems Lifetime. The flaw resides in the ApplicationID parameter, which any authenticated user could manipulate to access the Change Log of applications they are not authorized to view, exposing action histories performed by other users as well as application names.

The vulnerability was responsibly reported by Zbigniew Piotrak of the AFINE Team and has since been remediated by OutSystems in Lifetime version 11.28.2.3955. There is no indication of active exploitation; this is a coordinated disclosure with a patch already available. Organizations running OutSystems Lifetime should update to the fixed version to prevent unauthorized users from enumerating application metadata and audit log details.

## Mentioned in this report

- Vulnerabilities: CVE-2026-40127

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-40127

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1c826b00-1458-5b8e-9bd2-f601a07f59d6/outsystems-lifetime-patches-authorization-bypass-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
