CVE-2026-7891 Details
Description
Rejected reason: This CVE has been retracted. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.
A vulnerability in the VerySecureApp created with Mendix Studio Pro, in versions up to and including 11.8.0 Beta, allows unauthorized data access due to improper authorization settings. The application permits anonymous users in the MyFirstModule to access all stored records, despite the absence of explicit permissions for that role. This issue arises because all Mendix entities must be made publicly available by anonymous users, and earlier versions of Mendix Studio Pro automatically apply user inheritance rules to the anonymous role without clear documentation. As a result, sensitive information can be accessed through standard Mendix runtime requests, creating a risk of GDPR violations, fraud, phishing, reputational harm, and potential data breach notifications.
Users are advised to review and adjust the authorization settings in their Mendix applications. This includes checking entity access rules, module role mappings, and the permissions assigned to anonymous and newly registered users. If sensitive data is exposed, access should be restricted immediately and logged for any signs of misuse.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | CVE Rejected | [email protected] |
| Sep 22, 2026 | CVE Modified | [email protected] |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 7, 2026 | New CVE Received | [email protected] |