OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicious filename containing JavaScript code. The vulnerability exists in all locations where a file can be attached and prepared for upload to the server.

This issue was fixed in OutSystems Service Center version 11.41.2

Project Subscriptions

Vendors Products
Outsystems Subscribe
Service Center Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 17 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicious filename containing JavaScript code. The vulnerability exists in all locations where a file can be attached and prepared for upload to the server. This issue was fixed in OutSystems Service Center version 11.41.2
Title DOM-based Cross-Site Scripting in OutSystems Service Center
First Time appeared Outsystems
Outsystems service Center
Weaknesses CWE-79
CPEs cpe:2.3:a:outsystems:service_center:*:*:*:*:*:*:*:*
Vendors & Products Outsystems
Outsystems service Center
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-08-17T14:45:46.006Z

Reserved: 2026-04-09T10:15:00.973Z

Link: CVE-2026-40126

cve-icon Vulnrichment

Updated: 2026-08-17T14:45:39.920Z

cve-icon NVD

Status : Received

Published: 2026-08-17T12:18:25.000

Modified: 2026-08-17T15:16:55.133

Link: CVE-2026-40126

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T14:00:21Z

Weaknesses