CVE-2024-33500: Siemens Mendix
Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.11.0), Mendix Applications using Mendix 10 (V10.6) (All versions < V10.6.9), Mendix Applications using Mendix 9 (All versions >= V9.3.0 < V9.24.22). Affected applications could allow users with the capability to manage a role to elevate the access rights of users with that role. Successful exploitation requires to guess the id of a target role which contains the elevated access rights.
Affected products
- Siemens Mendix: from 10..0, before 10.11.0 (fixed in 10.11.0); from 10.6, before 10.6.9 (fixed in 10.6.9); from 9.3.0, before 9.24.22 (fixed in 9.24.22)
- Siemens Mendix Applications Using Mendix 10: before V10.11.0 (fixed in V10.11.0)
- Siemens Mendix Applications Using Mendix 10 v10.6: before V10.6.9 (fixed in V10.6.9)
- Siemens Mendix Applications Using Mendix 9: from V9.3.0, before V9.24.22 (fixed in V9.24.22)
Published 2024-06-11. Last modified 2026-06-17.