IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-814963: Insecure Inherited Permission in Mendix (Revoked)

UNKNOWN
CVSS 0.0
Date 2026-09-22T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-7891 0.0 unknown
CVE-2026-7891. This CVE has been retracted. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected application-specific attribute.

// Remediations (4)

Patch: Review mendix access rules knowing that System.User has built-in platform-enforced access rules that
Review mendix access rules knowing that System.User has built-in platform-enforced access rules that cannot be overridden or restricted by access rules defined on a specialization. Check updated documentation for further details
Mitigation: Any security model relying solely on XPath constraints on a System.User specialization to restrict a
Any security model relying solely on XPath constraints on a System.User specialization to restrict access should be revised to enforce restrictions at the App Security role-management configuration level instead.
Patch: Review mendix access rules knowing that System.User has built-in platform-enforced access rules that
Review mendix access rules knowing that System.User has built-in platform-enforced access rules that cannot be overridden or restricted by access rules defined on a specialization. Check updated documentation for further details
Mitigation: Any security model relying solely on XPath constraints on a System.User specialization to restrict a
Any security model relying solely on XPath constraints on a System.User specialization to restrict access should be revised to enforce restrictions at the App Security role-management configuration level instead.

// References