Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-77226— Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint

Quick assessment

Affected
Camunda Camunda 7
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Camunda 7.24.0 至 7.24.15 版本(不含 7.24.15)的管理 Web 应用程序的初始设置端点中存在不正确的授权漏洞。具体而言,SetupResource 在判断系统是否已完成初始设置时,仅统计 camunda-admin 组的直接成员,而未识别所有已配置的管理员账户。未认证的远程攻击者可利用此逻辑缺陷,调用用户创建设置端点,在 camunda-admin 组为空但系统实际已完全配置的情况下创建新的管理员账户,从而导致账户接管,并可能以引擎服务用户身份部署业务流程或执行脚本。

CVSS 8.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77226

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to call the setup user-create endpoint and create a new administrator account when the camunda-admin group is empty but the system is fully administered, resulting in account takeover and potential process deployment or script execution as the engine's service user.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Camunda Camunda 7 7.24.0 ~ 7.24.15 -

II. Public POCs for CVE-2026-77226

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77226

请登录查看更多情报信息。

Other References for CVE-2026-77226 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-77226

No comments yet


Leave a comment