CVE-2026-77226
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to call the setup user-create endpoint and create a new administrator account when the camunda-admin group is empty but the system is fully administered, resulting in account takeover and potential process deployment or script execution as the engine's service user.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Camunda | Camunda 7 | 7.24.0 < 7.24.15 | affected |
Weaknesses
- CWE-863: Incorrect Authorization
References
- https://codeant.ai/security-research/camunda-empty-admin-group-cve-2026-77226
- https://docs.camunda.org/enterprise/download/
- https://www.vulncheck.com/advisories/camunda-incorrect-authorization-via-setupresource-endpoint
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.