Post

Siemens Mendix Runtime Vulnerability Advisory

Siemens Mendix Runtime Vulnerability Advisory

Siemens Mendix Runtime Vulnerability Advisory

Source: CISA
Date Published: July 28, 2026

Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications. 🚨

A common misconfiguration identified is with the anonymous user role with a System.User entity to gain access to all stored records, even though no access rights are explicitly configured on that role. The following versions of Siemens Mendix Runtime are affected: Mendix Runtime vers:all/* (CVE-2026-7891). Critical Infrastructure Sectors impacted include Critical Manufacturing. These systems are deployed worldwide. 🌍

Siemens recommends Mendix developers to review their access rules based on updated documentation. As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. 🔒 Any security model relying solely on XPath constraints on a System.User specialization to restrict access should be revised to enforce restrictions at the App Security role-management configuration level instead. Developers should review Mendix access rules, knowing that System.User has built-in platform-enforced access rules that cannot be overridden or restricted by access rules defined on a specialization. Further details are available in the updated documentation. The relevant CWE is CWE-277 Insecure Inherited Permissions. Siemens ProductCERT reported this vulnerability to CISA.

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Organizations should minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Control system networks and remote devices should be located behind firewalls and isolated from business networks. 🔥 When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also, recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at CISA.gov.

Read full article

This post is licensed under CC BY 4.0 by the author.