Siemens Product Security Update Advisory
Overview
Two vulnerabilities have been identified in Siemens products. A specific privilege inheritance behavior in the System.User entity of Mendix Runtime is not sufficiently documented, which could result in excessive access privileges being granted, potentially leading to the exposure of sensitive information or privilege escalation. This vulnerability is identified as CVE-2026-7891 and has a CVSS v3.1 Score of 9.1.
SIMATIC S7-PLCSIM Advanced fails to properly handle large volumes of multicast network traffic, which can lead to memory exhaustion and, consequently, a denial of service. This vulnerability is identified as CVE-2026-54429 and has a CVSS v3.1 Score of 7.4.
Affected Products
Mendix Runtime: All versions.SIMATIC S7-PLCSIM Advanced: All versions.
Impact
CVE-2026-7891: Exposure of sensitive information and privilege escalation.CVE-2026-54429: Denial of service.
Patch Status
As of July 30, 2026, no Vulnerability Patch has been released for these vulnerabilities.
Mitigation Measures
- For
CVE-2026-7891, review access control configurations that rely solely on theXPathconstraints of theSystem.Userspecialized entity. - Apply access restrictions in the
Mendix App Securityrole management settings. - Refer to the updated
Mendixdocumentation to review and modify access rules related toSystem.User. - For
CVE-2026-54429, restrict multicast traffic on network segments whereSIMATIC S7-PLCSIM Advancedis installed. - Disable the
S7-PLCSIM Virtual Switchbinding on the network adapter in use. - Use the
SoftbusorPLCSIMnetwork mode, which does not receive external network packets.