Impact
The vulnerability exists in the Mendix Runtime across all versions and stems from a documentation gap that does not adequately explain how to configure access rules securely, potentially leading developers to set overly permissive rules for the System.User entity. This can expose sensitive user data or allow privilege escalation within deployed Mendix applications.
Affected Systems
The affected product is Siemens Mendix Runtime. All published versions of the runtime are impacted by this documentation gap, as any instance may propagate default or misconstrued access rules for System.User. The impact indicates the possibility of data exposure and is rated with a CVSS score of 9.1, showing very high severity.
Risk and Exploitability
The CVSS score of 9.1 identifies a critical risk, while the EPSS score indicates a very low but non‑zero exploitation likelihood. The vulnerability is not currently listed in CISA’s KEV catalog, suggesting no known widespread exploitation. The likely attack vector is a web request from an unauthenticated client to a Mendix application, based on the nature of access‑rule flaws, but this is inferred rather than directly documented.
OpenCVE Enrichment