Mendix · Mendix Studio Pro · CVE-2026-7891
**Name of the Vulnerable Software and Affected Versions**
Mendix Studio Pro versions prior to 11.8.0 Beta
**Description**
An authorization misconfiguration in the software allows unintended data exposure. Specifically, users with the anonymous user role in the `MyFirstModule` can gain access to all stored records, even when no access rights are explicitly configured for that role. This occurs because the software silently applies user inheritance rules to the anonymous user role, a behavior not explicitly detailed in the documentation.
**Recommendations**
Update to a version later than 11.8.0 Beta.