Article

    Cyber News / Article / Vulnerability in Lifetime software

    Vulnerability in Lifetime software
    CE
    CERT Polska-2026-05-25

    Vulnerability in Lifetime software

    CERT Polska has received a report about vulnerability in OutSystems Lifetime software and participated in coordination of its disclosure.

    The vulnerabilityCVE-2026-40127: OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user can read the Change Log containing actions performed by other users as well as application name of any application.

    This issue was fixed in OutSystems Lifetime version 11.28.2.3955

    We thank Zbigniew Piotrak (AFINE Team) for the responsible vulnerability report.

    Original source