Junglewise Threat Intelligence

CVE-2026-40127: OutSystems LifeTime authorization bypass in ApplicationID parameter

CVE-2026-40127 · Severity: info · CVSS 5.3 · Published 2026-05-25

Executive brief

OutSystems LifeTime, a management console for deploying and monitoring applications, contains a security flaw that allows users to view information they are not authorized to see. By manipulating application identifiers, any logged-in user can access change logs and application names belonging to other users or projects. This could lead to the exposure of sensitive operational history and internal application structures.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639, exists in OutSystems LifeTime due to insufficient validation of the 'ApplicationID' parameter. An authenticated attacker can modify this parameter in web requests to bypass authorization checks and access the Change Log of any application. This exposure includes the names of all applications and a history of actions performed by other users. The vulnerability is exploitable over the network with low privileges and requires no user interaction. The issue is resolved in OutSystems LifeTime version 11.28.2.3955.

Affected products

  • OutSystems LifeTime versions prior to 11.28.2.3955

Timeline

  • 2026-05-25: disclosed
  • 2026-05-25: advisory
  • 2026-05-25: patched: Fixed in version 11.28.2.3955

References