Article
Cyber News / Article / Vulnerability in Lifetime software

CE
CERT Polska-2026-05-25
Vulnerability in Lifetime software
CERT Polska has received a report about vulnerability in OutSystems Lifetime software and participated in coordination of its disclosure.
The vulnerabilityCVE-2026-40127: OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user can read the Change Log containing actions performed by other users as well as application name of any application.
This issue was fixed in OutSystems Lifetime version 11.28.2.3955
We thank Zbigniew Piotrak (AFINE Team) for the responsible vulnerability report.
Related articles
in
[email protected] (The Hacker News)Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
8 days ago
Ab
AbinayaWindows Remote Desktop Client Vulnerability Allows Attackers to Execute Remote Code
2 days ago
Gu
Guru BaranWindows BitLocker Vulnerability Allows Attackers to Execute Malicious Code Remotely
2 days ago
You might Also like

Tu
Tushar Subhra Dutta-2 days ago
Hackers Target Claude, Cursor and Codex AI Agents to Steal Tokens and Prompt Histories

in
[email protected] (The Hacker News)-2 days ago
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

Tu
Tushar Subhra Dutta-2 days ago
