Description
Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to call the setup user-create endpoint and create a new administrator account when the camunda-admin group is empty but the system is fully administered, resulting in account takeover and potential process deployment or script execution as the engine's service user.
Published: 2026-10-05
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: Account takeover enabling process deployment and script execution
Action: Immediate Patch
AI Analysis

Impact

An incorrect authorization flaw exists in the first‑run setup endpoint of the Camunda Admin web application. The SetupResource component incorrectly verifies setup availability by counting only direct members of the camunda‑admin group and ignores all configured administrators. An unauthenticated remote attacker can exploit this flaw to invoke the setup user‑create endpoint when the camunda‑admin group is empty but the system remains fully administered, resulting in the creation of a new administrator account. This enables the attacker to take over the process engine, deploy malicious processes, or execute arbitrary scripts as the service user. The vulnerability directly leads to full privileged compromise of the Camunda instance.

Affected Systems

Camunda 7 series, specifically versions 7.24.0 through 7.24.14, are affected. Users running 7.24.0 prior to 7.24.15 have not yet received the fix and remain at risk.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.2, indicating critical severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog at this time. The likely attack vector is remote, unauthenticated over HTTP, as the endpoint does not require prior authentication. If successfully exploited, an attacker gains full administrative control, enabling compromise of confidentiality, integrity, and availability for the entire Camunda deployment.

Generated by OpenCVE AI on October 5, 2026 at 22:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Camunda to version 7.24.15 or later to receive the corrective patch.
  • Verify that the camunda‑admin group is not empty; ensure all intended administrators are listed so the setup endpoint correctly identifies the availability state.
  • Restrict or disable the first‑run setup endpoints (e.g., /setup) until the system is patched, or enforce authentication to all setup APIs.
  • Continuously monitor logs for any unexpected account creation requests or unapproved usage of the setup API.

Generated by OpenCVE AI on October 5, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to call the setup user-create endpoint and create a new administrator account when the camunda-admin group is empty but the system is fully administered, resulting in account takeover and potential process deployment or script execution as the engine's service user.
Title Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-05T20:26:01.427Z

Reserved: 2026-08-20T18:25:46.944Z

Link: CVE-2026-77226

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T21:16:37.337

Modified: 2026-10-05T21:16:37.337

Link: CVE-2026-77226

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T22:45:18Z

Weaknesses