CVE-2026-77226: Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint

Published Oct 5, 2026
·
Updated

Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to call the setup user-create endpoint and create a new administrator account when the camunda-admin group is empty but the system is fully administered, resulting in account takeover and potential process deployment or script execution as the engine's service user.

Affected Software

1 affected component
Camunda Camunda>=7.24.0<7.24.15

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Camunda to a version that resolves this vulnerability.

    Fixed in 7.24.15

Event History

Oct 5, 2026
CVE Published
via MITRE·08:26 PM
Data Sourced
via MITRE·08:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Camunda 7.24.0 through versions before 7.24.15 are affected when the Admin web application's first-run setup endpoint is reachable and the camunda-admin group has no direct members. The condition can exist even when administrators are configured through other mechanisms.

2

Does an attacker need credentials or user interaction?

No. The vulnerability is exploitable remotely without authentication or user interaction, although exploitation depends on the setup-availability logic treating the system as unconfigured.

3

What can an attacker do after exploiting the flaw?

An attacker can invoke the setup user-creation endpoint to create a new administrator account. This can lead to account takeover and may allow process deployment or script execution as the engine's service user.

4

How can I determine whether my deployment is at risk?

Check whether the affected Camunda version is in use, whether the Admin web application's setup endpoint is exposed, and whether camunda-admin has zero direct members. A deployment may still be administered through configured administrators while meeting the empty direct-membership condition.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203