CVE-2026-7891
The VerySecureApp made by DIVD using Mendix Studio Pro 11.8.0 Beta allows unintended data exposure due to authorization misconfiguration. The VerySecureApp allows anonymous users of the MyFirstModule with the anonymous user role to gain access to all stored records, even though no access rights are explicitly configured on that role. Anonymous users are required to make a Mendix Entity available publicly. All versions of Mendix Studio Pro up to 11.8.0 Beta silently make an Anonymous user role follow user inheritance rules, without mentioning this explicitly in the documentation.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-277, CWE-277
- Published
- 2026-05-07
- Last modified
- 2026-07-14
Affected products
- DIVD VerySecureApp
- Siemens Mendix Runtime
Weakness type
Related vulnerabilities
- CVE-2026-9046 — A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store...
- CVE-2025-32092 — Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0...
- CVE-2025-65111 — SpiceDB's LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results
- CVE-2025-64185 — Open OnDemand RPM packages create world writable locations
- CVE-2025-24327 — Insecure inherited permissions for some Intel(R) Rapid Storage Technology Application before...
- CVE-2025-11554 — Portabilis i-Educar User Type AccessLevelController.php insecure inherited permissions
- CVE-2025-58437 — Coder's privilege escalation vulnerability could lead to a cross workspace compromise
- CVE-2025-9039 — Information Disclosure in Amazon ECS Container Agent