Siemens Product Security Update Advisory

Siemens Product Security Update Advisory

Overview


Two vulnerabilities have been identified in Siemens products. A specific privilege inheritance behavior in the System.User entity of Mendix Runtime is not sufficiently documented, which could result in excessive access privileges being granted, potentially leading to the exposure of sensitive information or privilege escalation. This vulnerability is identified as CVE-2026-7891 and has a CVSS v3.1 Score of 9.1.

SIMATIC S7-PLCSIM Advanced fails to properly handle large volumes of multicast network traffic, which can lead to memory exhaustion and, consequently, a denial of service. This vulnerability is identified as CVE-2026-54429 and has a CVSS v3.1 Score of 7.4.

Affected Products


  • Mendix Runtime: All versions.
  • SIMATIC S7-PLCSIM Advanced: All versions.

Impact


  • CVE-2026-7891: Exposure of sensitive information and privilege escalation.
  • CVE-2026-54429: Denial of service.

Patch Status


As of July 30, 2026, no Vulnerability Patch has been released for these vulnerabilities.

Mitigation Measures


  • For CVE-2026-7891, review access control configurations that rely solely on the XPath constraints of the System.User specialized entity.
  • Apply access restrictions in the Mendix App Security role management settings.
  • Refer to the updated Mendix documentation to review and modify access rules related to System.User.
  • For CVE-2026-54429, restrict multicast traffic on network segments where SIMATIC S7-PLCSIM Advanced is installed.
  • Disable the S7-PLCSIM Virtual Switch binding on the network adapter in use.
  • Use the Softbus or PLCSIM network mode, which does not receive external network packets.