Siemens Mendix Studio Pro

MonitorCVSS 5.4ICS-CERT ICSA-26-188-04Jun 30, 2026
SiemensOil & gas
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityHigh
User InteractionRequired
Summary

Mendix Studio Pro versions before V11.12 contain a file parsing vulnerability that can be triggered when the application reads a specially crafted malicious project file during the build pipeline. This allows arbitrary code execution in the context of the user running Studio Pro. Siemens has released patches for Mendix Studio Pro 10.24.x (fix in 10.24.21) and 11.6.x (fix in 11.6.7), but no fixes are planned for versions 10.11-10.23, 11.0-11.5, and 11.7-11.11.

What this means
What could happen
An attacker could execute arbitrary code on a developer's workstation by crafting a malicious Mendix Studio Pro project file. This could compromise the developer's system, steal credentials, or inject backdoors into application builds.
Who's at risk
Development teams using Mendix Studio Pro for application development, particularly those in oil and gas or other critical infrastructure sectors. This affects developers and engineers who create or build applications using Studio Pro versions 10.11 through 10.23, all of 10.24 before 10.24.21, 11.0 through 11.5, all of 11.6 before 11.6.7, and 11.7 through 11.11.
How it could be exploited
An attacker creates a malicious Mendix Studio Pro project file with specially crafted content. When a developer opens the project in Studio Pro (v10.x or v11.0-v11.5, or v11.7-v11.11), the application parses the file during the build process and executes arbitrary code with the privileges of the developer's user account.
Prerequisites
  • Developer must open a malicious Mendix Studio Pro project file
  • Affected version of Mendix Studio Pro must be installed
  • File parsing must occur during build or project loading
no authentication requiredlow complexity attackno patch available for majority of affected versionsaffects development environment credentials and build pipeline
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
2 with fix24 EOL
ProductAffected VersionsFix Status
Mendix Studio Pro 10.11All versionsNo fix (EOL)
Mendix Studio Pro 10.12All versionsNo fix (EOL)
Mendix Studio Pro 10.13All versionsNo fix (EOL)
Mendix Studio Pro 10.14All versionsNo fix (EOL)
Mendix Studio Pro 10.15All versionsNo fix (EOL)
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDDo not open Mendix Studio Pro project files from untrusted sources until your version is updated
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Mendix Studio Pro 10.24.x to version 10.24.21 or later
HOTFIXUpdate Mendix Studio Pro 11.6.x to version 11.6.7 or later
Mitigations - no patch available
0/1
The following products have reached End of Life with no planned fix: Mendix Studio Pro 10.11, Mendix Studio Pro 10.12, Mendix Studio Pro 10.13, Mendix Studio Pro 10.14, Mendix Studio Pro 10.15, Mendix Studio Pro 10.16, Mendix Studio Pro 10.17, Mendix Studio Pro 10.18, Mendix Studio Pro 10.19, Mendix Studio Pro 10.20, Mendix Studio Pro 10.21, Mendix Studio Pro 10.22, Mendix Studio Pro 10.23, Mendix Studio Pro 11.0, Mendix Studio Pro 11.1, Mendix Studio Pro 11.10, Mendix Studio Pro 11.11, Mendix Studio Pro 11.2, Mendix Studio Pro 11.3, Mendix Studio Pro 11.4, Mendix Studio Pro 11.5, Mendix Studio Pro 11.7, Mendix Studio Pro 11.8, Mendix Studio Pro 11.9. Apply the following compensating controls:
HARDENINGFor Mendix Studio Pro versions 10.11 through 10.23 and 11.0 through 11.5, 11.7 through 11.11: discontinue use or migrate to patched versions (11.6.7 or later, or 10.24.21 or later) as no fix is planned
API: /api/v1/advisories/4bee582f-5d08-49f3-9125-a5738d1f0286

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.