Siemens Mendix Runtime Advisory Revoked: CVE-2026-7891 Retracted After Re-investigation
Initial critical alert found to be expected platform configuration; no vulnerability present
Key Takeaways
- CVE-2026-7891 has been officially retracted following re-investigation.
- The reported insecure inherited permissions behavior is expected platform configuration and does not expose protected attributes.
- Siemens Mendix Runtime product status is marked as not_affected.
- No known public exploitation has been reported.
- Siemens recommends protecting network access and following industrial security operational guidelines as general best practices.
Quick answers
- What happened?
- CISA and Siemens ProductCERT issued and subsequently revoked an advisory for CVE-2026-7891 affecting Siemens Mendix Runtime. Re-investigation confirmed the reported insecure inherited permissions behavior is expected platform configuration and does not expose protected application-specific attributes. The vulnerability has been officially retracted, with product status marked as not_affected.
- What should defenders do?
- No patch or specific mitigation is required for this retracted vulnerability. Siemens recommends protecting network access to devices with appropriate mechanisms and following the company's operational guidelines for industrial security, available at https://www.siemens.com/cert/operational-guidelines-industrial-security and https://www.siemens.com/industrialsecurity.
- Which vulnerabilities are involved?
- CVE-2026-7891
An advisory was initially published regarding CVE-2026-7891 in Siemens Mendix Runtime, classified with a CVSS base score of 9.1 (CRITICAL) and categorized under Insecure Inherited Permissions (CWE-277). The vulnerability was reported by Siemens ProductCERT and assigned to CISA. However, following re-investigation, both Siemens ProductCERT and CISA confirmed that the reported behavior is expected platform configuration and does not expose the protected attribute. Consequently, the advisory has been revoked and the CVE has been retracted. The affected product status is now marked as not_affected. Siemens reiterated general security recommendations, advising users to protect network access to devices with appropriate mechanisms and to follow the company's operational guidelines for industrial security. No known public exploitation of this vulnerability has been reported, and no patch is required given the retracted status.
Security Details
CVE-2026-7891 was initially reported as a critical vulnerability (CVSS 9.1) affecting Siemens Mendix Runtime with Insecure Inherited Permissions (CWE-277). Following re-investigation, both Siemens ProductCERT and CISA confirmed the behavior is expected platform configuration and does not expose protected attributes. The CVE has been officially retracted and the product status is marked as not_affected.
Mitigation
No patch or specific mitigation is required for this retracted vulnerability. Siemens recommends protecting network access to devices with appropriate mechanisms and following the company's operational guidelines for industrial security, available at https://www.siemens.com/cert/operational-guidelines-industrial-security and https://www.siemens.com/industrialsecurity.
Sources
CISA Advisories
Siemens Mendix Runtime (Update A)
Sep 24, 2026 · 12:00
Original link
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


