OutSystems Service Center patches DOM XSS flaw
A DOM-based XSS vulnerability in OutSystems Service Center let low-privileged attackers inject JavaScript via malicious file names, now fixed in version 11.41.2.
CERT Polska coordinated the disclosure of CVE-2026-40126, a DOM-based Cross-Site Scripting vulnerability in OutSystems Service Center. The flaw allows a low-privileged attacker to exploit any file upload location within the application by crafting a filename containing malicious JavaScript code, which is then executed in the context of the victim's browser session when processed by the application.
The vulnerability affects all areas of the software where file attachments can be prepared for upload, broadening the potential attack surface within affected deployments. OutSystems has released version 11.41.2 to remediate the issue. The vulnerability was responsibly reported by Zbigniew Piotrak of the AFINE Team, and there is no indication in the advisory of active exploitation in the wild.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/08/CVE-2026-40126
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free