CISA AdvisoriesSecurity updates
Siemens Mendix Runtime (Update A)
View CSAF
Summary
This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.
The following versions of Siemens Mendix Runtime are affected:
Siemens Mendix Runtime vers:all/* (CVE-2026-7891)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.1
Siemens
Siemens Mendix Runtime
Insecure Inherited Permissions
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-7891
This CVE has been retracted. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected application-specific attribute.
View CVE Details
Affected Products
Siemens Mendix Runtime (Update A)
Vendor:
Siemens
Product Version:
Siemens Siemens Mendix Runtime: vers:all/*
Product Status:
not_affected
Remediations
Mitigation
Vulnerability is rejected as re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected application-specific attribute (Vulnerable Code Not Present).
Mitigation
As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for industrial security and following recommendations in the product manuals.
https://www.siemens.com/cert/operatio