CVE-2026-77226: Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint
Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to call the setup user-create endpoint and create a new administrator account when the camunda-admin group is empty but the system is fully administered, resulting in account takeover and potential process deployment or script execution as the engine's service user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Camundato a version that resolves this vulnerability.Fixed in 7.24.15
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Camunda 7.24.0 through versions before 7.24.15 are affected when the Admin web application's first-run setup endpoint is reachable and the camunda-admin group has no direct members. The condition can exist even when administrators are configured through other mechanisms.
Does an attacker need credentials or user interaction?
No. The vulnerability is exploitable remotely without authentication or user interaction, although exploitation depends on the setup-availability logic treating the system as unconfigured.
What can an attacker do after exploiting the flaw?
An attacker can invoke the setup user-creation endpoint to create a new administrator account. This can lead to account takeover and may allow process deployment or script execution as the engine's service user.
How can I determine whether my deployment is at risk?
Check whether the affected Camunda version is in use, whether the Admin web application's setup endpoint is exposed, and whether camunda-admin has zero direct members. A deployment may still be administered through configured administrators while meeting the empty direct-membership condition.