top of page
perceptive_background_267k.jpg

Siemens Mendix Runtime

Published:

28 July 2026 at 14:00:00

Alert date:

28 July 2026 at 18:04:03

Source:

cisa.gov

Click to open the original link from this advisory

Enterprise Applications, Critical Infrastructure, Identity & Access

A critical vulnerability (CVE-2026-7891) has been identified in Siemens Mendix Runtime affecting all versions. The issue stems from inadequate documentation for access rules related to the System.User entity, which can lead developers to apply overly permissive access configurations. This misconfiguration can result in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications. A common misconfiguration involves the anonymous user role gaining access to all stored records via System.User even without explicit access rights. The vulnerability scores a CVSS v3.1 base score of 9.1 (CRITICAL) with network-accessible attack vector requiring no privileges or user interaction. Siemens recommends developers review access rules, enforce restrictions at the App Security role-management level, and consult updated documentation. CISA republished this advisory from Siemens ProductCERT SSA-814963 to increase visibility.

Technical details

Mitigation steps:

Affected products:

Siemens Mendix Runtime

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page