CERT Polska disclosed CVE-2026-40126, a DOM-based cross-site scripting flaw in OutSystems Service Center that affects all versions before 11.41.2. The vulnerability can be triggered by a low-privileged attacker who uploads a file with a filename containing malicious JavaScript, allowing script injection in areas where files are attached and prepared for upload to the server.
OutSystems has fixed the issue in Service Center 11.41.2. CERT Polska said it coordinated disclosure of the bug, and credited Zbigniew Piotrak of the AFINE Team with responsibly reporting the vulnerability; a separate security notice amplified the advisory but did not add exploitation or impact details beyond the CERT disclosure.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CERT Polska published CVE-2026-40126 on 17 August 2026, disclosing a DOM-based cross-site scripting vulnerability in OutSystems Service Center. The notice states the issue is classified as CWE-79 and can be exploited through malicious filenames in file upload workflows.
OutSystems remediated CVE-2026-40126 in Service Center version 11.41.2. The vulnerability affects all versions before 11.41.2.
Zbigniew Piotrak of the AFINE Team responsibly reported a DOM-based cross-site scripting vulnerability in OutSystems Service Center to CERT Polska, which then coordinated disclosure. The flaw allows a low-privileged attacker to inject JavaScript via a malicious filename during file upload preparation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.