SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-40126

MEDIUM · CVSS 4.8 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

OutSystems Service Center is susceptible to a DOM-based Cross-Site Scripting (XSS) vulnerability that allows low-privileged attackers to exploit the system by uploading files with malicious JavaScript filenames. This could lead to unauthorized script execution in the context of the user’s session, potentially compromising sensitive data. Organizations using affected versions of OutSystems Service Center should prioritize patching to version 11.41.2 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-40126
Severity
MEDIUM
CVSS
4.8
EPSS
0.30%
Java

Original NVD Description

OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicious filename containing JavaScript code. The vulnerability exists in all locations where a file can be attached and prepared for upload to the server. This issue was fixed in OutSystems Service Center version 11.41.2