Impact
The vulnerability arises from an insufficiently documented access rule configuration for the System.User entity in Mendix Runtime. Because the official guidance does not make clear the special behavior of this entity, developers may unintentionally grant read permissions to anonymous roles or other entities. This oversight can allow an attacker to read sensitive user data or elevate privileges within any deployed application using the runtime, thereby compromising confidentiality and potentially enabling further exploitation.
Affected Systems
The affected product is Siemens Mendix Runtime. All published versions of the runtime are impacted by this documentation gap, as any instance of the runtime may propagate the default or misconstrued access rules for the System.User entity.
Risk and Exploitability
The CVSS score of 9.1 indicates very high severity. While the EPSS score is less than 1%, the possibility of data exposure makes this a critical issue that should not be overlooked. It is not listed in CISA's KEV catalog. The attack vector is likely a web request from an unauthenticated client to the application exposed by the runtime; this inference is based on the nature of the vulnerability and typical exposure patterns for access-rule flaws.
OpenCVE Enrichment