← Zurück zur CVE-Suche

CVE-2026-40127

OutSystems Lifetime

Beschreibung

OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any application. This issue was fixed in OutSystems Lifetime version 11.28.2.3955

CVSS 5.3EPSS 0.35100000000000003%Risiko 0.55
Quelle öffnen
Veröffentlicht
2026-05-25 11:16:17
Betroffene Versionen
<11.28.2.3955
Typ
Kritische Software
Zuletzt geändert
2026-08-11 07:17:30
Vektor
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X