Authorization Misconfiguration in VerySecureApp by DIVD
CVE-2026-7891

9.1CRITICAL

Key Information:

Vendor

Siemens

Vendor
CVE Published:
7 May 2026

What is CVE-2026-7891?

The VerySecureApp, developed by DIVD using Mendix Studio Pro 11.8.0 Beta, exhibits a significant authorization misconfiguration that allows anonymous users to access sensitive data without proper access rights. Specifically, users in the MyFirstModule with the anonymous role can view all stored records, breaching the intended access controls. This issue arises as all versions of Mendix Studio Pro up to 11.8.0 Beta inadvertently enforce user inheritance rules for the Anonymous user role, without clear documentation. As a result, individuals accessing the application may unintentionally expose confidential information. It is crucial for users and administrators to review access settings and consider mitigation strategies to safeguard data integrity.

Affected Version(s)

Mendix Runtime 0

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.