Vulnerabilities & Exploits · Web App Attack

Authenticated Users Can Read OutSystems Audit History

A login is enough to cross tenant lines inside OutSystems Lifetime. The bug does not open the door to outsiders; it lets any authenticated user pull other users’ change logs and application names, so the usual “it requires authentication” reading misses the exposure.

CERT Polska says the issue is an authorization bypass through a user-controlled ApplicationID parameter, tracked as CVE-2026-40127. It affects OutSystems Lifetime and was fixed in version 11.28.2.3955.

For teams that use Lifetime as the oversight layer, that turns low-privilege access into a way to map the application estate and inspect audit actions from inside the admin plane.

1 source · May 25

CVE-2026-40127

NVD KEV

Timeline

Sources

Part of the PlainSec briefing for 2026-05-25

Every edition of this story: Authenticated Users Can Read OutSystems Audit History

More from today