CVE-2026-40126: DOM-based XSS in OutSystems Service Center via malicious file upload filenames

CVE-2026-40126 (TL-2026-2043) is a medium-severity software vulnerability scored CVSS 4.8, first published 2026-08-17. It has no confirmed attribution, affects OutSystems Service Center, references 1 CVE (CVE-2026-40126), maps to 10 MITRE ATT&CK techniques (T1027, T1036, T1059.007), and is covered by 9 detection rules and 10 indicators of compromise.

Key facts for TL-2026-2043

Threat ID
TL-2026-2043
Severity
MEDIUM
CVSS
4.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Status
PATCHED
Category
VULNERABILITY
First published
2026-08-17
Last reviewed
2026-08-17
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
10

CERT Polska coordinated the disclosure of CVE-2026-40126, a DOM-based cross-site scripting flaw (CWE-79, CVSS 4.0 base score 4.8) affecting all versions of OutSystems Service Center before 11.41.2. A low-privileged attacker can upload a file whose filename contains JavaScript code at any file-attachment point, and when that filename is rendered in the DOM it executes in the browser session of whoever views it. OutSystems shipped a fix in Service Center 11.41.2; no public PoC or active exploitation has been reported.

How CVE-2026-40126 works

OutSystems Service Center — the administration console for the OutSystems low-code platform — contains a DOM-based cross-site scripting vulnerability (CWE-79, Improper Neutralization of Input During Web Page Generation) tracked as CVE-2026-40126. Per the coordinated-disclosure advisory published by CERT Polska on 17 August 2026, a low-privileged authenticated attacker can exploit the flaw by uploading a file whose filename contains embedded JavaScript at any location in the application where a file can be attached and prepared for upload. The advisory states the vulnerability is present at 'all locations where a file can be attached and prepared for upload to the server,' but does not disclose the precise DOM sink or rendering path that turns the unsanitized filename into executed script — no proof-of-concept exploit has been published.

NIST's NVD record assigns a CVSS v4.0 vector of AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N (base score 4.8, MEDIUM). The vector indicates the flaw is network-reachable and low-complexity, but requires the attacker to already hold low-level privileges (PR:L) and requires a second party's active interaction (UI:A) — consistent with a stored/DOM XSS where the payload only fires when another user (potentially a higher-privileged Service Center administrator) views the malicious filename in the UI. The explicit User Interaction: Active requirement means exploitation depends on a victim rendering or opening a file listing that contains the attacker-controlled filename, functionally an execution-through-interaction step rather than an unattended trigger. The Subsequent System (SC/SI) sub-scores of Low reflect that the resulting script execution can affect the confidentiality/integrity of the victim's browser session in Service Center, which functionally enables session-token theft and privilege escalation against whichever user renders the attacker-controlled filename.

The vulnerability was discovered and responsibly reported by Zbigniew Piotrak of the AFINE Team, a certified penetration-testing group with 150+ published CVEs, and coordinated to disclosure by CERT Polska. OutSystems remediated the issue in Service Center 11.41.2. This is the second OutSystems vulnerability from the same researcher/CERT Polska coordination pairing in 2026: CVE-2026-40127 (CWE-639, Authorization Bypass Through User-Controlled Key, in OutSystems LifeTime, fixed in 11.28.2.3955) was disclosed on 25 May 2026 and confirmed present in AFINE's own published research index alongside CVE-2026-40126 — a distinct flaw in a distinct OutSystems component, included here only as sourced context for the same research lineage, not as an affected product of this CVE. As of the advisory's publication date, CVE-2026-40126 is absent from CISA's Known Exploited Vulnerabilities catalog, consistent with CERT Polska's statement that no active exploitation or public PoC exists.

MITRE ATT&CK techniques used in TL-2026-2043

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Execution

T1059.007 Command and Scripting Interpreter: JavaScript; T1204 User Execution

Collection

T1185 Browser Session Hijacking

Initial Access

T1190 Exploit Public-Facing Application

Credential Access

T1539 Steal Web Session Cookie

Resource Development

T1588.006 Vulnerabilities

Reconnaissance

T1592.002 Gather Victim Host Information: Software; T1595.002 Active Scanning: Vulnerability Scanning

Affected products and versions in CVE-2026-40126

  • OutSystems — Service Center
    Vulnerable versions: all versions before 11.41.2
    Fixed in: 11.41.2

Remediation for CVE-2026-40126

Patches

  • OutSystems Service Center 11.41.2

Immediate actions

  • Upgrade OutSystems Service Center to version 11.41.2 or later
  • Until patched, audit recently uploaded filenames at all file-attachment points for embedded script-like content (e.g. angle brackets, 'javascript:', event-handler strings)

Longer-term hardening

  • Enforce server-side and client-side sanitization/output-encoding of user-supplied filenames before they are rendered in any DOM context
  • Deploy a Content Security Policy on the Service Center UI to restrict inline script execution
  • Review authorization boundaries so content uploaded by a low-privileged account cannot be rendered unsanitized to higher-privileged users

CVEs associated with CVE-2026-40126

CVE-2026-40126

Weaknesses (CWE) in CVE-2026-40126

CWE-79

Timeline of CVE-2026-40126

  • CERT Polska publishes coordinated disclosure of CVE-2026-40127 (Authorization Bypass Through User-Controlled Key, CWE-639) in OutSystems LifeTime, also reported by AFINE Team's Zbigniew Piotrak — the same researcher/coordinator pairing behind CVE-2026-40126.
  • AFINE Team's public research index and GitHub research repository list CVE-2026-40126 alongside CVE-2026-40127 as the two OutSystems disclosures credited to Zbigniew Piotrak, corroborating the CERT Polska attribution.
  • CVE-2026-40126 is absent from CISA's Known Exploited Vulnerabilities catalog as of the advisory date, consistent with CERT Polska's statement of no active exploitation and no public PoC.
  • OutSystems publishes its own vulnerability advisory (vulnerability_rpm_6669) for CVE-2026-40126, referenced by NVD as the official vendor fix reference.
  • OutSystems Service Center 11.41.2, which resolves CVE-2026-40126, is confirmed as the fixed version at time of advisory publication.
  • CVE.org/NVD publish the CVE-2026-40126 record (12:18:25 UTC) with CWE-79 and a CVSS v4.0 base score of 4.8 (MEDIUM).
  • CERT Polska publishes the coordinated-disclosure advisory for CVE-2026-40126, a DOM-based XSS in OutSystems Service Center reported by Zbigniew Piotrak of AFINE Team.

Sources cited for CVE-2026-40126

More in vulnerability

Detection coverage for TL-2026-2043

As of 2026-08-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2043 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats