Siemens Mendix Runtime
Mendix documentation inadequately describes the special behavior of the System.User entity and how access rules inherit permissions, leaving developers without sufficient guidance to configure access rules securely. This documentation gap commonly results in misconfigured access rules that unintentionally expose sensitive user data or enable privilege escalation. A known misconfiguration is granting the anonymous user role access to System.User records, allowing unauthorized access to all stored user data. The root cause is that System.User has built-in platform-enforced access rules that cannot be overridden or restricted by access rules defined on specializations of that entity. Developers must review access rules knowing this constraint and revise any security models that rely solely on XPath constraints on System.User specializations to enforce restrictions at the App Security role-management configuration level instead.
- Access to the deployed Mendix application (typically HTTP/HTTPS)
- Application must use misconfigured access rules on System.User or its specializations
Patching may require device reboot — plan for process interruption
/api/v1/advisories/fb9c3bfd-3b32-4319-9943-dc638357668eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.