CVE-2026-40126: DOM-based XSS in OutSystems Service Center via malicious file upload filenames
CVE-2026-40126 (TL-2026-2043) is a medium-severity software vulnerability scored CVSS 4.8, first published 2026-08-17. It has no confirmed attribution, affects OutSystems Service Center, references 1 CVE (CVE-2026-40126), maps to 10 MITRE ATT&CK techniques (T1027, T1036, T1059.007), and is covered by 9 detection rules and 10 indicators of compromise.
Key facts for TL-2026-2043
- Threat ID
- TL-2026-2043
- Severity
- MEDIUM
- CVSS
- 4.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-08-17
- Last reviewed
- 2026-08-17
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 10
CERT Polska coordinated the disclosure of CVE-2026-40126, a DOM-based cross-site scripting flaw (CWE-79, CVSS 4.0 base score 4.8) affecting all versions of OutSystems Service Center before 11.41.2. A low-privileged attacker can upload a file whose filename contains JavaScript code at any file-attachment point, and when that filename is rendered in the DOM it executes in the browser session of whoever views it. OutSystems shipped a fix in Service Center 11.41.2; no public PoC or active exploitation has been reported.
How CVE-2026-40126 works
OutSystems Service Center — the administration console for the OutSystems low-code platform — contains a DOM-based cross-site scripting vulnerability (CWE-79, Improper Neutralization of Input During Web Page Generation) tracked as CVE-2026-40126. Per the coordinated-disclosure advisory published by CERT Polska on 17 August 2026, a low-privileged authenticated attacker can exploit the flaw by uploading a file whose filename contains embedded JavaScript at any location in the application where a file can be attached and prepared for upload. The advisory states the vulnerability is present at 'all locations where a file can be attached and prepared for upload to the server,' but does not disclose the precise DOM sink or rendering path that turns the unsanitized filename into executed script — no proof-of-concept exploit has been published.
NIST's NVD record assigns a CVSS v4.0 vector of AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N (base score 4.8, MEDIUM). The vector indicates the flaw is network-reachable and low-complexity, but requires the attacker to already hold low-level privileges (PR:L) and requires a second party's active interaction (UI:A) — consistent with a stored/DOM XSS where the payload only fires when another user (potentially a higher-privileged Service Center administrator) views the malicious filename in the UI. The explicit User Interaction: Active requirement means exploitation depends on a victim rendering or opening a file listing that contains the attacker-controlled filename, functionally an execution-through-interaction step rather than an unattended trigger. The Subsequent System (SC/SI) sub-scores of Low reflect that the resulting script execution can affect the confidentiality/integrity of the victim's browser session in Service Center, which functionally enables session-token theft and privilege escalation against whichever user renders the attacker-controlled filename.
The vulnerability was discovered and responsibly reported by Zbigniew Piotrak of the AFINE Team, a certified penetration-testing group with 150+ published CVEs, and coordinated to disclosure by CERT Polska. OutSystems remediated the issue in Service Center 11.41.2. This is the second OutSystems vulnerability from the same researcher/CERT Polska coordination pairing in 2026: CVE-2026-40127 (CWE-639, Authorization Bypass Through User-Controlled Key, in OutSystems LifeTime, fixed in 11.28.2.3955) was disclosed on 25 May 2026 and confirmed present in AFINE's own published research index alongside CVE-2026-40126 — a distinct flaw in a distinct OutSystems component, included here only as sourced context for the same research lineage, not as an affected product of this CVE. As of the advisory's publication date, CVE-2026-40126 is absent from CISA's Known Exploited Vulnerabilities catalog, consistent with CERT Polska's statement that no active exploitation or public PoC exists.
MITRE ATT&CK techniques used in TL-2026-2043
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Execution
T1059.007 Command and Scripting Interpreter: JavaScript; T1204 User Execution
Collection
T1185 Browser Session Hijacking
Initial Access
T1190 Exploit Public-Facing Application
Credential Access
T1539 Steal Web Session Cookie
Resource Development
Reconnaissance
T1592.002 Gather Victim Host Information: Software; T1595.002 Active Scanning: Vulnerability Scanning
Affected products and versions in CVE-2026-40126
- OutSystems — Service Center
Vulnerable versions: all versions before 11.41.2
Fixed in: 11.41.2
Remediation for CVE-2026-40126
Patches
- OutSystems Service Center 11.41.2
Immediate actions
- Upgrade OutSystems Service Center to version 11.41.2 or later
- Until patched, audit recently uploaded filenames at all file-attachment points for embedded script-like content (e.g. angle brackets, 'javascript:', event-handler strings)
Longer-term hardening
- Enforce server-side and client-side sanitization/output-encoding of user-supplied filenames before they are rendered in any DOM context
- Deploy a Content Security Policy on the Service Center UI to restrict inline script execution
- Review authorization boundaries so content uploaded by a low-privileged account cannot be rendered unsanitized to higher-privileged users
CVEs associated with CVE-2026-40126
Weaknesses (CWE) in CVE-2026-40126
CWE-79
Timeline of CVE-2026-40126
- CERT Polska publishes coordinated disclosure of CVE-2026-40127 (Authorization Bypass Through User-Controlled Key, CWE-639) in OutSystems LifeTime, also reported by AFINE Team's Zbigniew Piotrak — the same researcher/coordinator pairing behind CVE-2026-40126.
- AFINE Team's public research index and GitHub research repository list CVE-2026-40126 alongside CVE-2026-40127 as the two OutSystems disclosures credited to Zbigniew Piotrak, corroborating the CERT Polska attribution.
- CVE-2026-40126 is absent from CISA's Known Exploited Vulnerabilities catalog as of the advisory date, consistent with CERT Polska's statement of no active exploitation and no public PoC.
- OutSystems publishes its own vulnerability advisory (vulnerability_rpm_6669) for CVE-2026-40126, referenced by NVD as the official vendor fix reference.
- OutSystems Service Center 11.41.2, which resolves CVE-2026-40126, is confirmed as the fixed version at time of advisory publication.
- CVE.org/NVD publish the CVE-2026-40126 record (12:18:25 UTC) with CWE-79 and a CVSS v4.0 base score of 4.8 (MEDIUM).
- CERT Polska publishes the coordinated-disclosure advisory for CVE-2026-40126, a DOM-based XSS in OutSystems Service Center reported by Zbigniew Piotrak of AFINE Team.
Sources cited for CVE-2026-40126
- Vulnerability in OutSystems Service Center software
- CVE-2026-40126 record
- NVD CVE-2026-40126 Detail (CVSS v4.0, CWE-79)
- OutSystems vulnerability advisory (RPM-6669)
- OutSystems LifeTime 11.28.2.3955 release notes (fix reference cited by NVD)
- AFINE Team research repository — CVE-2026-40126 and CVE-2026-40127 entries
- AFINE — Certified Penetration Testing Team, 150+ CVEs Published
- AFINE Vulnerability Research index (lists CVE-2026-40127 alongside this research lineage)
- CWE-79: Improper Neutralization of Input During Web Page Generation
- Vulnerability in Lifetime software (CVE-2026-40127, related AFINE Team/CERT Polska disclosure)
- CISA Known Exploited Vulnerabilities Catalog (checked — CVE-2026-40126 not listed)
More in vulnerability
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)
- GitLab AI Gateway critical RCE via prompt template sandbox escape (CVE-2026-90970)
- CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD
- Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on Firmware 7.00-13.60
- Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)
Detection coverage for TL-2026-2043
As of 2026-08-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2043 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.