Authenticated Users Can Read OutSystems Audit History
A login is enough to cross tenant lines inside OutSystems Lifetime. The bug does not open the door to outsiders; it lets any authenticated user pull other users’ change logs and application names, so the usual “it requires authentication” reading misses the exposure.
CERT Polska says the issue is an authorization bypass through a user-controlled ApplicationID parameter, tracked as CVE-2026-40127. It affects OutSystems Lifetime and was fixed in version 11.28.2.3955.
For teams that use Lifetime as the oversight layer, that turns low-privilege access into a way to map the application estate and inspect audit actions from inside the admin plane.