CVE-2026-40126
DOM-based Cross-Site Scripting in OutSystems Service Center
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicious filename containing JavaScript code. The vulnerability exists in all locations where a file can be attached and prepared for upload to the server. This issue was fixed in OutSystems Service Center version 11.41.2
| CWE | CWE-79 |
| Vendor | outsystems |
| Product | service center |
| Published | Aug 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for outsystems service center
Be the first to know when new unknown vulnerabilities affecting outsystems service center are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
OutSystems / Service Center
0 < 11.41.2
References
Credits
Zbigniew Piotrak (AFINE Team)