PT-2026-106239 · Camunda · Camunda
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Camunda versions 7.24.0 through 7.24.14
Description
An incorrect authorization issue exists in the Admin web application's first-run setup endpoint. The
SetupResource incorrectly determines if the setup process is available by counting only direct members of the camunda-admin group instead of recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to access the setup user-create endpoint and create a new administrator account if the camunda-admin group is empty, even if the system is already fully administered. This can lead to account takeover, unauthorized process deployment, or script execution as the engine's service user.Recommendations
Update Camunda to version 7.24.15.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Camunda