The VerySecureApp made by DIVD using Mendix Studio Pro 11.8.0 Beta allows unintended data exposure due to authorization misconfiguration. The VerySecureApp allows anonymous users of the MyFirstModule with the anonymous user role to gain access to all stored records, even though no access rights are explicitly configured on that role. Anonymous users are required to make a Mendix Entity available publicly. All versions of Mendix Studio Pro up to 11.8.0 Beta silently make an Anonymous user role follow user inheritance rules, without mentioning this explicitly in the documentation.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 07 May 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authorization Misconfiguration Allowing Anonymous Data Exposure in VerySecureApp |
Thu, 07 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The VerySecureApp made by DIVD using Mendix Studio Pro 11.8.0 Beta allows unintended data exposure due to authorization misconfiguration. The VerySecureApp allows anonymous users of the MyFirstModule with the anonymous user role to gain access to all stored records, even though no access rights are explicitly configured on that role. Anonymous users are required to make a Mendix Entity available publicly. All versions of Mendix Studio Pro up to 11.8.0 Beta silently make an Anonymous user role follow user inheritance rules, without mentioning this explicitly in the documentation. | |
| Weaknesses | CWE-277 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: DIVD
Published:
Updated: 2026-05-07T21:07:22.206Z
Reserved: 2026-05-05T21:09:08.070Z
Link: CVE-2026-7891
No data.
Status : Received
Published: 2026-05-07T22:16:37.070
Modified: 2026-05-07T22:16:37.070
Link: CVE-2026-7891
No data.
OpenCVE Enrichment
Updated: 2026-05-07T22:30:36Z
Weaknesses