Authorization bypass through user-controlled key in Lifetime - CVE-2026-40127

 

Authorization bypass through user-controlled key in Lifetime - CVE-2026-40127

Published: June 1, 2026


Vulnerability identifier: #VU133109
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40127
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in /lifetime/Application_ChangeLog.aspx when handling requests with the ApplicationId parameter. A remote user can manipulate the ApplicationId parameter to disclose sensitive information.

The issue affects application change log data, and predictable sequential identifiers facilitate automated enumeration of change logs across the environment.


Affected software

Lifetime

How to mitigate CVE-2026-40127

Install security update from vendor's website.

Lifetime - update to 11.28.2

External References

Related Security Bulletins