Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-77226: Camunda 7 lets attacker create admin account
CVE-2026-77226 · published 5 days ago
Summary
If Camunda version 7.24.0 through 7.24.14 is used, the first‑time setup page does not correctly check who is allowed to run it. An attacker who can reach the server can call that page and add a new administrator when the admin group is empty, giving them full control over the workflow engine. Upgrade to Camunda 7.24.15 or later, or restrict access to the setup endpoint until the system is fully configured.
What to do
- Update camunda camunda 7 to version 7.24.15 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| camunda | camunda 7 | < 7.24.15 |
Original advisory text
Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint
Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to call the setup user-create endpoint and create a new administrator account when the camunda-admin group is empty but the system is fully administered, resulting in account takeover and potential process deployment or script execution as the engine's service user.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-863Incorrect Authorization
Timeline
Published5 Oct 2026
Updated11 Oct 2026
First seen5 Oct 2026
Track software like this
Free during beta