


Perceptive Security
SOC/SIEM Consultancy

Siemens Mendix Runtime
Published:
28 juli 2026 om 12:00:00
Alert date:
28 juli 2026 om 16:04:03
Source:
cisa.gov
Enterprise Applications, Critical Infrastructure, Identity & Access
A critical vulnerability (CVE-2026-7891) has been identified in Siemens Mendix Runtime affecting all versions. The issue stems from inadequate documentation for access rules related to the System.User entity, which can lead developers to apply overly permissive access configurations. This misconfiguration can result in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications. A common misconfiguration involves the anonymous user role gaining access to all stored records via System.User even without explicit access rights. The vulnerability scores a CVSS v3.1 base score of 9.1 (CRITICAL) with network-accessible attack vector requiring no privileges or user interaction. Siemens recommends developers review access rules, enforce restrictions at the App Security role-management level, and consult updated documentation. CISA republished this advisory from Siemens ProductCERT SSA-814963 to increase visibility.
Technical details
Mitigation steps:
Affected products:
Siemens Mendix Runtime
Related links:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-02.json
https://www.cve.org/CVERecord?id=CVE-2026-7891
https://cwe.mitre.org/data/definitions/277.html
https://www.siemens.com/cert/operational-guidelines-industrial-security
https://www.siemens.com/industrialsecurity
https://www.siemens.com/cert/advisories
https://www.siemens.com/productcert/terms-of-use
https://www.cisa.gov/notification
https://www.cisa.gov/privacy-policy
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
