Executive brief
Siemens Mendix Runtime is a low-code application development platform used to build enterprise applications. A reported vulnerability claiming insecure inherited permissions has been revoked by Siemens after re-investigation, which confirmed the behavior was normal platform configuration. No security risk or exposure exists, and no user action is required.
Technical details
CVE-2026-7891 initially reported an insecure inherited permissions issue (CWE-277) in Siemens Mendix Runtime affecting all versions. The vulnerability was assigned a CVSS v3.1 score of 9.1 (critical), suggesting network-based unauthenticated access to sensitive data. However, Siemens ProductCERT re-investigated the claim and determined the reported behavior constitutes expected platform configuration and does not actually expose protected application-specific attributes. The CVE has been rejected and the advisory revoked; no vulnerable code is present. No mitigation or patching is necessary beyond standard security hygiene (network isolation, firewall protection).
Affected products
- Siemens Mendix Runtime all versions
Timeline
- 2026-07-14: disclosed: Initial publication of advisory
- 2026-09-22: other: Advisory revoked; CVE rejected after re-investigation
- 2026-09-24: other: Update A - Final revocation after Siemens ProductCERT rejected CVE-2026-7891