Impact
An incorrect authorization flaw exists in the first‑run setup endpoint of the Camunda Admin web application. The SetupResource component incorrectly verifies setup availability by counting only direct members of the camunda‑admin group and ignores all configured administrators. An unauthenticated remote attacker can exploit this flaw to invoke the setup user‑create endpoint when the camunda‑admin group is empty but the system remains fully administered, resulting in the creation of a new administrator account. This enables the attacker to take over the process engine, deploy malicious processes, or execute arbitrary scripts as the service user. The vulnerability directly leads to full privileged compromise of the Camunda instance.
Affected Systems
Camunda 7 series, specifically versions 7.24.0 through 7.24.14, are affected. Users running 7.24.0 prior to 7.24.15 have not yet received the fix and remain at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.2, indicating critical severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog at this time. The likely attack vector is remote, unauthenticated over HTTP, as the endpoint does not require prior authentication. If successfully exploited, an attacker gains full administrative control, enabling compromise of confidentiality, integrity, and availability for the entire Camunda deployment.
OpenCVE Enrichment