Skip to content
CVE-2026-77226 in Camunda Allows Unauthorized Admin Account Creation

CVE-2026-77226 in Camunda Allows Unauthorized Admin Account Creation

First seen 6 Oct 2026, 01:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 02:26 UTC
  • •CVE-2026-77226 is a critical authorization vulnerability in Camunda 7.24.0.
  • •Unauthenticated attackers can create admin accounts if the camunda-admin group is empty.
  • •A patch was released on 2026-10-05; immediate action is recommended.

Camunda 7.24.0 before 7.24.15 contains a high-priority authorization vulnerability (CVE-2026-77226) in its Admin web application's first-run setup endpoint. An unauthenticated remote attacker can exploit this flaw to create a new administrator account if the camunda-admin group is empty, despite other administrators being configured. This could lead to account takeover, allowing the attacker to deploy processes or execute scripts as the engine's service user. The vulnerability affects internet-facing deployments of the Admin web application. A patch was released on 2026-10-05, but the urgency of applying it cannot be fully assessed due to the lack of KEV, SSVC, and EPSS status. Organizations are advised to restrict access to the setup endpoint and verify administrator accounts until the patch is applied.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-05
CVE-2026-77226 published
Camunda disclosed a critical authorization vulnerability affecting version 7.24.0, allowing unauthorized admin account creation.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-77226 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions of Camunda are affected?
Camunda 7.24.0 before 7.24.15 is affected by CVE-2026-77226.
How can I mitigate this vulnerability?
Upgrade to Camunda 7.24.15 or later, restrict access to the setup endpoint, and verify administrator accounts.
Is there any active exploitation reported?
No active exploitation has been reported as of now, but the vulnerability is critical.