Junglewise Threat Intelligence

CVE-2026-7891: Siemens Mendix Runtime insecure inherited permissions in System.User entity

CVE-2026-7891 · Severity: critical · CVSS 9.1 · Published 2026-05-07

Vendors: Siemens.

Executive brief

Siemens Mendix Runtime is a low-code application development platform used to build enterprise applications. A reported vulnerability claiming insecure inherited permissions has been revoked by Siemens after re-investigation, which confirmed the behavior was normal platform configuration. No security risk or exposure exists, and no user action is required.

Technical details

CVE-2026-7891 initially reported an insecure inherited permissions issue (CWE-277) in Siemens Mendix Runtime affecting all versions. The vulnerability was assigned a CVSS v3.1 score of 9.1 (critical), suggesting network-based unauthenticated access to sensitive data. However, Siemens ProductCERT re-investigated the claim and determined the reported behavior constitutes expected platform configuration and does not actually expose protected application-specific attributes. The CVE has been rejected and the advisory revoked; no vulnerable code is present. No mitigation or patching is necessary beyond standard security hygiene (network isolation, firewall protection).

Affected products

  • Siemens Mendix Runtime all versions

Timeline

  • 2026-07-14: disclosed: Initial publication of advisory
  • 2026-09-22: other: Advisory revoked; CVE rejected after re-investigation
  • 2026-09-24: other: Update A - Final revocation after Siemens ProductCERT rejected CVE-2026-7891

References

Related threats