CISA flags Siemens Mendix Studio Pro code-injection CVE-2026-48192
Remediation is uneven: Siemens names two patched trains and gives the remaining affected versions no timetable.
TL;DR
CISA republished Siemens ProductCERT SSA-779310 for CVE-2026-48192, a CVSS 5.4 code-injection flaw triggered when Siemens Mendix Studio Pro processes malicious project files during build pipeline execution. The affected list spans Mendix Studio Pro 10.11 through 10.23, 10.24 before V10.24.21 and 11.0 through 11.11; fixes are listed only for V10.24.21 and V11.6.7. Contractors, independent software vendors and defense-industrial-base teams using Mendix for critical manufacturing or energy applications should treat project files as hostile build inputs.
CISA's July 7 page is a direct republication of Siemens ProductCERT SSA-779310, provided as-is from the vendor advisory. The substantive issue is still clear: CVE-2026-48192 sits in Siemens Mendix Studio Pro, where a specially crafted project file can trigger arbitrary code execution in the user's context when the project is opened and run locally and the build pipeline processes it. Siemens rates the CWE-94 flaw at CVSS v3.1 5.4, medium. The operational blast radius follows the user's access.
The affected list is broad: Mendix Studio Pro 10.11 through 10.23, 10.24 before V10.24.21, and 11.0 through 11.11. Siemens lists vendor fixes at V10.24.21 or later and V11.6.7 or later, says additional fix versions are in preparation, and gives no timetable in the CISA text for other affected trains. That leaves teams outside those two patched lines with a remediation question rather than a clean patch instruction, especially the 11.0 through 11.5 and 11.7 through 11.9 trains the advisory does not tie to a dated fix.
The reason this belongs in a supply-chain queue is simple. CISA tags the deployment as worldwide, with Critical Manufacturing and Energy as the listed sectors. Mendix Studio Pro is a development tool that can sit near continuous integration and delivery pipelines, source code and deployment artifacts for those applications. Asset inventories built around controllers, servers and remote access paths can miss that tier. A malicious project file reaching the build workflow is quieter than an internet-facing controller, but the result CISA describes is code execution on the machine doing the building.
Practitioners have a narrow first move: update eligible 10.24 and 11.6 installations to V10.24.21 or later and V11.6.7 or later, respectively. Where no fix is listed, apply Siemens' countermeasures, restrict opening and running external projects in the build path, and monitor Siemens ProductCERT for the future fix versions. CISA's standard control-system advice on network exposure still matters. This exposure starts earlier, in development, so the control has to start there.
Published ·Deep Fathom