OCTOBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-40127

UNKNOWN · CVSS N/A EPSS 0.32%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-05-25 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. Exploitation may require the attacker to be authenticated.

CVE
CVE-2026-40127
Severity
UNKNOWN
CVSS
N/A
EPSS
0.32%

Original NVD Description

OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, canĀ read the Change Log containing actions performed by other users as well as application name of any application. This issue was fixed in OutSystems Lifetime versionĀ 11.28.2.3955