CVE-2026-48192: Code Injection
A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions), Mendix Studio Pro 10.12 (All versions), Mendix Studio Pro 10.13 (All versions), Mendix Studio Pro 10.14 (All versions), Mendix Studio Pro 10.15 (All versions), Mendix Studio Pro 10.16 (All versions), Mendix Studio Pro 10.17 (All versions), Mendix Studio Pro 10.18 (All versions), Mendix Studio Pro 10.19 (All versions), Mendix Studio Pro 10.20 (All versions), Mendix Studio Pro 10.21 (All versions), Mendix Studio Pro 10.22 (All versions), Mendix Studio Pro 10.23 (All versions), Mendix Studio Pro 10.24 (All versions < V10.24.21), Mendix Studio Pro 11.0 (All versions), Mendix Studio Pro 11.1 (All versions), Mendix Studio Pro 11.10 (All versions), Mendix Studio Pro 11.11 (All versions), Mendix Studio Pro 11.2 (All versions), Mendix Studio Pro 11.3 (All versions), Mendix Studio Pro 11.4 (All versions), Mendix Studio Pro 11.5 (All versions), Mendix Studio Pro 11.6 (All versions < V11.6.7), Mendix Studio Pro 11.7 (All versions), Mendix Studio Pro 11.8 (All versions), Mendix Studio Pro 11.9 (All versions). Affected versions of Mendix Studio Pro do not properly validate or sanitize project files processed during the build pipeline. This could allow an attacker who tricks a user into opening and running a specially crafted malicious project locally on their system to execute arbitrary code in the context of that user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48192?
The severity of CVE-2026-48192 is medium with a score of 5.4.
What types of attacks can exploit CVE-2026-48192?
CVE-2026-48192 can be exploited through code injection attacks due to its vulnerabilities in Mendix Studio Pro.
How do I fix CVE-2026-48192?
To fix CVE-2026-48192, you should upgrade to the latest version of Mendix Studio Pro that addresses this vulnerability.
What versions of Mendix Studio Pro are affected by CVE-2026-48192?
All versions of Mendix Studio Pro from 10.11 to 10.16 are affected by CVE-2026-48192.
What is the impact of CVE-2026-48192 on data integrity?
CVE-2026-48192 can result in a high impact on data integrity due to the potential for unauthorized code execution.