CVE-2026-7891
CRITICALVerySecureApp < 1.1.0 - Unauthenticated Data Exposure via Mendix Entity Inheritance Misconfiguration
Title source: llmDescription
A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
https://csirt.divd.nl/DIVD-2026-00006/
Mitigation mitigation
https://www.divd.nl/mendix.html
Scores
CVSS v3
9.1
EPSS
0.0027
EPSS Percentile
19.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-277
Status
published
Products (2)
DIVD/VerySecureApp
< 1.1.0
Siemens/Mendix Runtime
Published
May 07, 2026
Tracked Since
May 08, 2026