Siemens Mendix System.User Access Docs Flaw
A Siemens Mendix Runtime documentation gap can lead developers to misconfigure access rules on System.User, exposing sensitive data or enabling privilege escalation.
Siemens has disclosed a documentation deficiency in Mendix Runtime concerning the System.User entity's special access-control behavior. Because the official documentation does not clearly explain that System.User has built-in, platform-enforced permissions that cannot be overridden by developer-defined access rules on specializations, application developers may unknowingly configure overly permissive rules. A common real-world misconfiguration involves granting the anonymous user role access via a System.User specialization, inadvertently exposing all stored user records even when no explicit access rights were configured for that role.
This issue, tracked as CVE-2026-7891 and classified under CWE-277 (Insecure Inherited Permissions), affects all versions of Siemens Mendix Runtime. Siemens recommends that developers revise any security model relying on XPath constraints applied to System.User specializations, instead enforcing restrictions at the App Security role-management configuration level, and consult updated Mendix documentation for guidance. There is no evidence of active exploitation; this is a proactive vendor disclosure aimed at preventing insecure application configurations across the worldwide Mendix deployment base, primarily impacting the critical manufacturing sector per CISA's advisory categorization.
No indicators of compromise, threat actors, or malware are associated with this advisory. The risk stems from developer misconfiguration enabled by inadequate documentation rather than a code-level vulnerability, making remediation a matter of application-level review and reconfiguration rather than patching.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free