Junglewise Threat Intelligence

CVE-2026-48192: Siemens Mendix Studio Pro code injection in project file parsing

CVE-2026-48192 · Severity: medium · CVSS 5.4 · Published 2026-06-30

Vendors: Siemens.

Executive brief

Mendix Studio Pro is a development environment used to build business applications. A security flaw allows an attacker to create a malicious project file that, if opened and run by a developer, can execute unauthorized commands on their computer. This could lead to a full compromise of the developer's workstation and any data they have access to.

Technical details

A code injection vulnerability (CWE-94) exists in Mendix Studio Pro due to improper validation and sanitization of project files during the build pipeline. The vulnerability is triggered when the application parses a specially crafted malicious project file. An attacker requires high privileges and user interaction (tricking a user into opening and running the project) to achieve arbitrary code execution in the context of the local user. Siemens has released patches for versions 10.24 (V10.24.21) and 11.6 (V11.6.7), while other versions currently have no planned fix.

Affected products

  • Siemens Mendix Studio Pro 10.11 through 10.23 All versions
  • Siemens Mendix Studio Pro 10.24 versions < V10.24.21
  • Siemens Mendix Studio Pro 11.0 through 11.5 All versions
  • Siemens Mendix Studio Pro 11.6 versions < V11.6.7
  • Siemens Mendix Studio Pro 11.7 through 11.11 All versions

Timeline

  • 2026-06-30: disclosed: Initial advisory publication by Siemens and NVD.
  • 2026-06-30: patched: Fixes released for versions 10.24.21 and 11.6.7.

References

Related threats