PT-2026-71960 · Outsystems · Lifetime+1

·

CVE-2026-40126

·

Published

2026-08-11

·

Updated

2026-08-17

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions OutSystems Service Center versions prior to 11.41.2 OutSystems Lifetime versions prior to 11.28.2.3955
Description OutSystems Service Center is subject to a DOM-based Cross-Site Scripting (XSS) issue, where a low-privileged attacker can execute JavaScript code by uploading a file with a malicious filename. This occurs in any location where files are attached for server upload.
OutSystems Lifetime contains an authorization bypass flaw involving the ApplicationID parameter. This allows any authenticated user to access the Change Log, exposing application names and actions performed by other users.
Recommendations Update OutSystems Service Center to version 11.41.2. Update OutSystems Lifetime to version 11.28.2.3955.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40126

Affected Products

Lifetime
Hp Service Center