OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-77226

HIGH · CVSS 8.1 EPSS 0.69% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

An incorrect authorization vulnerability in Camunda 7.24.0 prior to 7.24.15 allows unauthenticated remote attackers to exploit the first-run setup endpoint, enabling them to create a new administrator account even when the camunda-admin group is empty. This flaw can lead to account takeover, allowing attackers to deploy processes or execute scripts with the privileges of the service user. Organizations using affected versions of Camunda should prioritize patching to mitigate the risk of unauthorized access and potential system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77226
Severity
HIGH
CVSS
8.1
EPSS
0.69%

Original NVD Description

Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to call the setup user-create endpoint and create a new administrator account when the camunda-admin group is empty but the system is fully administered, resulting in account takeover and potential process deployment or script execution as the engine's service user.