Redpacketsecurity CVE-2026-77226 in Camunda Allows Unauthorized Admin Account Creation
Article Content
- •CVE-2026-77226 is a critical authorization vulnerability in Camunda 7.24.0.
- •Unauthenticated attackers can create admin accounts if the camunda-admin group is empty.
- •A patch was released on 2026-10-05; immediate action is recommended.
Camunda 7.24.0 before 7.24.15 contains a high-priority authorization vulnerability (CVE-2026-77226) in its Admin web application's first-run setup endpoint. An unauthenticated remote attacker can exploit this flaw to create a new administrator account if the camunda-admin group is empty, despite other administrators being configured. This could lead to account takeover, allowing the attacker to deploy processes or execute scripts as the engine's service user. The vulnerability affects internet-facing deployments of the Admin web application. A patch was released on 2026-10-05, but the urgency of applying it cannot be fully assessed due to the lack of KEV, SSVC, and EPSS status. Organizations are advised to restrict access to the setup endpoint and verify administrator accounts until the patch is applied.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-77226 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What versions of Camunda are affected?
How can I mitigate this vulnerability?
Is there any active exploitation reported?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…