Security1 publisher2 min readPublished
CVE-2026-7891 in Siemens Mendix Runtime is retracted as expected platform configuration
CISA revoked its Siemens Mendix Runtime advisory and marked all versions not affected by CVE-2026-7891, now retracted as expected configuration. OT and application teams holding tickets for it can close them with no Runtime upgrade to schedule.
The Watch · Security desk

What happened
- A re-investigation found the reported behavior is expected platform configuration and does not expose the protected application-specific attribute.
- The advisory states that CVE-2026-7891, the identifier assigned to the reported issue, has been retracted.
- Siemens ProductCERT was the party that reported the issue to CISA, according to the advisory's acknowledgments.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Remediation tickets for CVE-2026-7891 can close against the not_affected status, with no Runtime upgrade to fit into a plant maintenance window.
- cost Because the entry named every Runtime version, the cleanup lands on every Mendix estate that logged it, as scanner findings and risk-register entries to clear.
- contradiction A reviewer who reads only the recommended-practices section of the revoked page could reopen a closed ticket, since that section still urges defense against exploitation.
There is nothing here for an attacker to use [2]. CISA said no known public exploitation specifically targeting the issue had been reported to it [7].
The scope was the whole product. The entry covered Mendix Runtime at vers:all/*, meaning every version, and listed the Critical Manufacturing sector with worldwide deployment [5][10]. It now resolves the same way everywhere. Every version carries the not_affected status, and the rejection is labeled "Vulnerable Code Not Present" [4]. No fixed release is listed, because there is nothing to fix [4].
The timeline on the page is short. The revision history holds one entry, the initial release on 2026-07-14 [11], while the page itself is titled Update A [1]. CISA refers readers to Siemens security advisory SSA-814963, in HTML and in the machine-readable CSAF format [6]. The CISA page does not say whether the Siemens document has been revised to match.
Parts of the revoked page still describe a live flaw. It keeps the tag CWE-277, Insecure Inherited Permissions [8]. Its recommended practices still say CISA "recommends users take defensive measures to minimize the risk of exploitation of this vulnerability" [9]. Higher up, the same page says the vulnerability is rejected [4]. Siemens frames its advice to protect network access to devices as "a general security measure" [13], and that advice stands apart from this CVE.
This is a one-off correction to the advisory record. Application teams that changed Mendix settings as a precaution can keep or revert those changes on their own merits. The re-investigation classes the original behavior as expected platform configuration and finds the protected attribute unexposed [2].
What to watch
- Siemens revising SSA-814963, including its CSAF file, to carry the same rejected, not_affected status the CISA page shows.
- The public CVE record for CVE-2026-7891 showing the rejection, so findings keyed to the CVE ID clear without manual overrides.