Mendix User Rules Can Expose Records by Default

Mendix developers can think they have narrowed access to user data and still leave the platform's built-in System.User behavior wide open. The risk is a false sense of containment: anonymous-role configurations and XPath constraints on a System.User specialization do not override the platform's own access rules, so apps can expose stored user records or escalate privileges in ways the app model does not show. CISA and Siemens say Mendix documentation does not fully describe that special behavior. The advisory ties the issue to CVE-2026-7891 and says all Mendix Runtime versions are affected, with the common failure mode being an anonymous user role that reaches every stored record even when no rights were set on paper.

Part of the PlainSec briefing for 2026-07-28

Sources