Vulnerabilities & Exploits · Web App Attack
A login is enough to cross tenant lines inside OutSystems Lifetime. The bug does not open the door to outsiders; it lets any authenticated user pull other users’ change logs and application names, so the usual “it requires authentication” reading misses the exposure.
CERT Polska says the issue is an authorization bypass through a user-controlled ApplicationID parameter, tracked as CVE-2026-40127. It affects OutSystems Lifetime and was fixed in version 11.28.2.3955.
For teams that use Lifetime as the oversight layer, that turns low-privilege access into a way to map the application estate and inspect audit actions from inside the admin plane.
1 source · May 25
CERT Polska
Vulnerability in Lifetime software
Authorization Bypass Through User-Controlled Key vulnerability (CVE-2026-40127) has been found in OutSystems Lifetime software.
originalPart of the PlainSec briefing for 2026-05-25
Every edition of this story: Authenticated Users Can Read OutSystems Audit History