CVE-2026-7891CWE-277

A vulnerability has been identified in Mendix Runtime (All versions)

Critical · published May 7, 2026

CVSS v4.0
9.1
EPSS
0%
Percentile
19.4
In the wild
Unconfirmed
What it is

A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications.

The record
Technical detail
CVSS v4.0
9.1 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00273 · 19.4th percentile
Weakness
CWE-277 · Insecure Inherited Permissions
Published
2026-05-07T21:07Z
EPSS history
Timeline
  • 07 MAY 21:07Z
    A vulnerability has been identified in Mendix Runtime (All versions)
    cvelistv5