Outsystems · Lifetime · CVE-2026-40126
**Name of the Vulnerable Software and Affected Versions**
OutSystems Service Center versions prior to 11.41.2
OutSystems Lifetime versions prior to 11.28.2.3955
**Description**
OutSystems Service Center is subject to a DOM-based Cross-Site Scripting (XSS) issue, where a low-privileged attacker can execute JavaScript code by uploading a file with a malicious filename. This occurs in any location where files are attached for server upload.
OutSystems Lifetime contains an authorization bypass flaw involving the `ApplicationID` parameter. This allows any authenticated user to access the Change Log, exposing application names and actions performed by other users.
**Recommendations**
Update OutSystems Service Center to version 11.41.2.
Update OutSystems Lifetime to version 11.28.2.3955.