← Back to the live CVE advisory feed

CVE-2026-77226: Product identification pending

Severity
9.2 (CRITICAL)
Vendor
CAMUNDA
Affected versions
Before 7.24.15
Fixed version
7.24.15
Patch status
Patched
Published
2026-10-05T21:16:37.337
Modified
2026-10-05T21:16:37.337

Why it matters

This matters because the affected product may allow code execution. Prioritize systems that are internet-facing or have privileged access to other infrastructure.

Recommended admin actions

  • Prioritize validation immediately due to critical CVSS severity.
  • Compare installed versions against the affected version range in the advisory.
  • Treat internet-facing systems as higher priority.
  • Review logs for suspicious activity related to the affected application or component.

Technical summary

Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to call the setup user-create endpoint and create a new administrator account when the camunda-admin group is empty but the system is fully administered, resulting in account takeover and potential process deployment or script execution as the engine's service user.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: OCT 06, 2026 04:00 AM UTC
388 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-100103
Product identification pending PATCH
Reporter: SECURITY
10
CRITICAL
VIEW RECORD
CVE-2026-105484
X6000R
Reporter: CNA
10
CRITICAL
VIEW RECORD
CVE-2026-105636
plane PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-105691
penpot PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-105697
langflow PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-105740
langflow PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-88395
Product identification pending
Reporter: CVE
9.8
CRITICAL
VIEW RECORD
CVE-2026-105639
plane PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-105641
plane PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-97283
Advanced Post Manager PATCH
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-105637
plane PATCH
Reporter: SECURITY-ADVISORIES
9.6
CRITICAL
VIEW RECORD
CVE-2026-105763
twenty PATCH
Reporter: SECURITY-ADVISORIES
9.6
CRITICAL
VIEW RECORD
CVE-2026-100102
Product identification pending PATCH
Reporter: SECURITY
9.5
CRITICAL
VIEW RECORD
CVE-2026-103510
Product identification pending PATCH
Reporter: SECURITY
9.5
CRITICAL
VIEW RECORD
CVE-2026-105284
A3002MU
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-105285
A3002MU
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-102428
OrdaSoft Joomla CCK
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-103352
WP BASE Booking PATCH
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-21589
Bamboo Data Center PATCH
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-91107
openSIS-Classic
Reporter: HELP
9.3
CRITICAL
VIEW RECORD
CVE-2026-77226
Product identification pending PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-105638
plane PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-105640
plane PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-79820
HPE Integrated Lights-Out (iLO) 7
Reporter: SECURITY-ALERT
9
CRITICAL
VIEW RECORD
CVE-2026-92931
Product identification pending
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-101919
Product identification pending
Reporter: SECALERT
8.8
HIGH
VIEW RECORD
CVE-2026-105642
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-45524
Product identification pending
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-55280
Product identification pending
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-58835
Product identification pending
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-100511
VK Google Job Posting Manager PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-97257
Simple Event Planner PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-102775
Phoca Cart extension for Joomla
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-104892
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-104966
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-104968
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-104976
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-104979
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-105630
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-105632
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-104389
Sirv PATCH
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-104805
Mitel MiVoice Office 400
Reporter: VULNERABILITY
8.5
HIGH
VIEW RECORD
CVE-2026-63277
Product identification pending
Reporter: SECURITY
8.5
HIGH
VIEW RECORD
CVE-2026-104971
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.5
HIGH
VIEW RECORD
CVE-2026-103066
WP BASE Booking PATCH
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-105786
joplin PATCH
Reporter: SECURITY-ADVISORIES
8.5
HIGH
VIEW RECORD
CVE-2026-104706
Mitel MiVoice Office 400
Reporter: VULNERABILITY
8.4
HIGH
VIEW RECORD
CVE-2026-104809
Mitel MiVoice Office 400
Reporter: VULNERABILITY
8.4
HIGH
VIEW RECORD
CVE-2026-104810
Mitel MiVoice Office 400
Reporter: VULNERABILITY
8.4
HIGH
VIEW RECORD
CVE-2026-104811
Mitel MiVoice Office 400
Reporter: VULNERABILITY
8.4
HIGH
VIEW RECORD
CVE-2026-19184
Product identification pending
Reporter: VULNERABILITIES
8.4
HIGH
VIEW RECORD
CVE-2026-12171
Product identification pending PATCH
Reporter: 7FFCEE3D-2C14-4C3E-B844-86C6A321A158
8.4
HIGH
VIEW RECORD
CVE-2026-86671
Product identification pending
Reporter: EMO
8.4
HIGH
VIEW RECORD
CVE-2026-105762
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.3
HIGH
VIEW RECORD
CVE-2026-104978
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-94201
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
8.2
HIGH
VIEW RECORD
CVE-2026-104852
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-104970
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-104974
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-105634
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-105650
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-105783
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8
HIGH
VIEW RECORD
CVE-2026-77805
Product identification pending
Reporter: SECURITY
7.9
HIGH
VIEW RECORD
CVE-2026-19185
Product identification pending
Reporter: VULNERABILITIES
7.8
HIGH
VIEW RECORD
CVE-2026-49885
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-49933
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-49937
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-55266
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-55269
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-55270
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-55286
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-58815
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-58841
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-58854
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-58859
Product identification pending
Reporter: SECURITY
7.8
HIGH
VIEW RECORD
CVE-2026-104977
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-105764
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-104408
Product identification pending
Reporter: AUDIT
7.6
HIGH
VIEW RECORD
CVE-2026-104973
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-105628
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-97303
Product identification pending
Reporter: AUDIT
7.6
HIGH
VIEW RECORD
CVE-2026-105314
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-103507
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-104891
mppx-condition-gate PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-105631
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-93318
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-103334
Product identification pending
Reporter: AUDIT
7.5
HIGH
VIEW RECORD
CVE-2026-58865
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-105675
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-0461
Product identification pending
Reporter: PSIRT
7.5
HIGH
VIEW RECORD
CVE-2026-105744
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-105782
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-105635
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.4
HIGH
VIEW RECORD
CVE-2026-105643
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.3
HIGH
VIEW RECORD
CVE-2026-105649
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.3
HIGH
VIEW RECORD
CVE-2026-105651
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.3
HIGH
VIEW RECORD
CVE-2026-105679
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.3
HIGH
VIEW RECORD
CVE-2026-105773
Product identification pending PATCH
Reporter: 9119A7D8-5EAB-497F-8521-727C672E3725
7.3
HIGH
VIEW RECORD
CVE-2026-104890
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.2
HIGH
VIEW RECORD
CVE-2026-103349
Product Feed PRO for WooCommerce PATCH
Reporter: AUDIT
7.2
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.