PT-2026-106239 · Camunda · Camunda

·

CVE-2026-77226

·

Published

2026-10-05

·

Updated

2026-10-06

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Camunda versions 7.24.0 through 7.24.14
Description An incorrect authorization issue exists in the Admin web application's first-run setup endpoint. The SetupResource incorrectly determines if the setup process is available by counting only direct members of the camunda-admin group instead of recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to access the setup user-create endpoint and create a new administrator account if the camunda-admin group is empty, even if the system is already fully administered. This can lead to account takeover, unauthorized process deployment, or script execution as the engine's service user.
Recommendations Update Camunda to version 7.24.15.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77226

Affected Products

Camunda