Vulnerability Description
A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/html/ssa-814963.html
- https://csirt.divd.nl/DIVD-2026-00006/
- https://www.divd.nl/mendix.html
FAQ
What is CVE-2026-7891?
CVE-2026-7891 is a vulnerability with a CVSS score of 9.1 (CRITICAL). A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving develop...
How severe is CVE-2026-7891?
CVE-2026-7891 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-7891?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.