# OutSystems Service Center patches DOM XSS flaw

Published: 2026-08-17 · Severity: routine
Canonical: https://vorant.io/reports/f6027dd1-91dc-5db5-8dfd-d2a842384358/outsystems-service-center-patches-dom-xss-flaw

> A DOM-based XSS vulnerability in OutSystems Service Center let low-privileged attackers inject JavaScript via malicious file names, now fixed in version 11.41.2.

CERT Polska coordinated the disclosure of CVE-2026-40126, a DOM-based Cross-Site Scripting vulnerability in OutSystems Service Center. The flaw allows a low-privileged attacker to exploit any file upload location within the application by crafting a filename containing malicious JavaScript code, which is then executed in the context of the victim's browser session when processed by the application.

The vulnerability affects all areas of the software where file attachments can be prepared for upload, broadening the potential attack surface within affected deployments. OutSystems has released version 11.41.2 to remediate the issue. The vulnerability was responsibly reported by Zbigniew Piotrak of the AFINE Team, and there is no indication in the advisory of active exploitation in the wild.

## Mentioned in this report

- Vulnerabilities: CVE-2026-40126

Source reporting: https://cert.pl/en/posts/2026/08/CVE-2026-40126

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f6027dd1-91dc-5db5-8dfd-d2a842384358/outsystems-service-center-patches-dom-xss-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
