boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-77226

Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0069   51.4     —
AFFECTED
  Product    Versions  Fixed
  Camunda 7  7.24.0 –  —
TIMELINE
  Aug 20  Reserved by VulnCheck
  Oct 5   Published (CNA: VulnCheck)
  Oct 7   EXPLOIT PUBLISHED — CVE-2026-77226 (Camunda 7). Public exploit reference added.
CWE-863 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Awaiting Analysis

Description

Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to call the setup user-create endpoint and create a new administrator account when the camunda-admin group is empty but the system is fully administered, resulting in account takeover and potential process deployment or script execution as the engine's service user.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
August 20, 2026ReservedReserved by VulnCheck
October 5, 2026PublishedPublished (CNA: VulnCheck)
October 7, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-77226 (Camunda 7). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
CamundaCamunda 7—7.24.0—

Weaknesses

CWE-863

References (3)

Related

Authoritative record: CVE-2026-77226 at cve.org

Vendors: camunda

Weaknesses: CWE-863

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-77226 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.