Vulnerabilities · 112 days ago

Authenticated Users Can Read OutSystems Audit History

A login is enough to cross tenant lines inside OutSystems Lifetime. The bug does not open the door to outsiders; it lets any authenticated user pull other users’ change logs and application names, so the usual “it requires authentication” reading misses the exposure.

CERT Polska says the issue is an authorization bypass through a user-controlled ApplicationID parameter, tracked as CVE-2026-40127. It affects OutSystems Lifetime and was fixed in version 11.28.2.3955.

For teams that use Lifetime as the oversight layer, that turns low-privilege access into a way to map the application estate and inspect audit actions from inside the admin plane.

CVE-2026-40127

NVD KEV

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-05-25

Editions

Related stories