Skip to content

Security1 publisher2 min readPublished

CVE-2026-7891 in Siemens Mendix Runtime is retracted as expected platform configuration

CISA revoked its Siemens Mendix Runtime advisory and marked all versions not affected by CVE-2026-7891, now retracted as expected configuration. OT and application teams holding tickets for it can close them with no Runtime upgrade to schedule.

The Watch · Security desk

Illustration accompanying CVE-2026-7891 in Siemens Mendix Runtime is retracted as expected platform configuration

What happened

  • A re-investigation found the reported behavior is expected platform configuration and does not expose the protected application-specific attribute.
  • The advisory states that CVE-2026-7891, the identifier assigned to the reported issue, has been retracted.
  • Siemens ProductCERT was the party that reported the issue to CISA, according to the advisory's acknowledgments.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Remediation tickets for CVE-2026-7891 can close against the not_affected status, with no Runtime upgrade to fit into a plant maintenance window.
  • cost Because the entry named every Runtime version, the cleanup lands on every Mendix estate that logged it, as scanner findings and risk-register entries to clear.
  • contradiction A reviewer who reads only the recommended-practices section of the revoked page could reopen a closed ticket, since that section still urges defense against exploitation.

There is nothing here for an attacker to use [2]. CISA said no known public exploitation specifically targeting the issue had been reported to it [7].

The scope was the whole product. The entry covered Mendix Runtime at vers:all/*, meaning every version, and listed the Critical Manufacturing sector with worldwide deployment [5][10]. It now resolves the same way everywhere. Every version carries the not_affected status, and the rejection is labeled "Vulnerable Code Not Present" [4]. No fixed release is listed, because there is nothing to fix [4].

The timeline on the page is short. The revision history holds one entry, the initial release on 2026-07-14 [11], while the page itself is titled Update A [1]. CISA refers readers to Siemens security advisory SSA-814963, in HTML and in the machine-readable CSAF format [6]. The CISA page does not say whether the Siemens document has been revised to match.

Parts of the revoked page still describe a live flaw. It keeps the tag CWE-277, Insecure Inherited Permissions [8]. Its recommended practices still say CISA "recommends users take defensive measures to minimize the risk of exploitation of this vulnerability" [9]. Higher up, the same page says the vulnerability is rejected [4]. Siemens frames its advice to protect network access to devices as "a general security measure" [13], and that advice stands apart from this CVE.

This is a one-off correction to the advisory record. Application teams that changed Mendix settings as a precaution can keep or revert those changes on their own merits. The re-investigation classes the original behavior as expected platform configuration and finds the protected attribute unexposed [2].

What to watch

  • Siemens revising SSA-814963, including its CSAF file, to carry the same rejected, not_affected status the CISA page shows.
  • The public CVE record for CVE-2026-7891 showing the rejection, so findings keyed to the CVE ID clear without manual overrides.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories