<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
<title>Camunda — Security Notices</title>
<link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/</link>
<description>Security notices for Camunda 8</description>
<language>en</language>
<lastBuildDate>Tue, 06 Oct 2026 07:28:50 GMT</lastBuildDate>
<ttl>60</ttl>
<docs>http://www.rssboard.org/rss-specification</docs>
<atom:link href="https://unsupported.docs.camunda.io/8.7/rss/security/notices.xml" rel="self" type="application/rss+xml" />
<image>
<url>https://unsupported.docs.camunda.io/8.7/img/black-C.png</url>
<title>Camunda — Security Notices</title>
<link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/</link>
</image>

<item>
  <title>Notice 64</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-64</link>
  <guid isPermaLink="false">camunda-security-notice-64</guid>
  <pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate>
  <description>A remote code execution vulnerability was identified in Camunda&apos;s FEEL expression engine allowing execution of arbitrary code within the scope of a Camunda 8 server operating system process.</description>
  <category>Camunda Orchestration Cluster (Zeebe, Operate, Tasklist)</category>
  <category>Camunda Connectors</category>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>A remote code execution vulnerability was identified in Camunda's FEEL expression engine allowing execution of arbitrary code within the scope of a Camunda 8 server operating system process.</p> <p>Severity: Critical 9.9 (CVSS v3.1: AV<!-- -->:N<!-- -->/AC<!-- -->:L<!-- -->/PR<!-- -->:L<!-- -->/UI<!-- -->:N<!-- -->/S<!-- -->:C<!-- -->/C<!-- -->:H<!-- -->/I<!-- -->:H<!-- -->/A<!-- -->:H<!-- -->).</p> <p>This vulnerability was identified by Camunda's Security Team, with no known report or exploit beyond our own security investigation. A CVE identifier has been requested and this notice will be updated once it is assigned. For further details, see <a href="https://github.com/camunda/feel-scala/security/advisories/GHSA-vx3p-v6cf-vfjw" target="_blank" rel="noopener noreferrer">GHSA-vx3p-v6cf-vfjw</a>.</p> <h3 id="how-to-determine-if-the-installation-is-affected">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Orchestration Cluster ≤ 8.9.19 or ≤ 8.8.37</li> 
<li>Camunda Zeebe, Operate, or Tasklist ≤ 8.7.39</li> 
<li>Camunda Connectors ≤ 8.9.10, ≤ 8.8.19, or ≤ 8.7.25</li> 
<li>Web Modeler ≤ 8.9.8, or ≤ 8.8.19</li> 
</ul> <p>Any component that bundles <code>org.camunda.feel:feel-engine</code> up to and including 1.22.0 is affected. Versions older than the ones listed above, including versions that have reached end of maintenance, are also affected, with the exception of Web Modeler, where versions below 8.8.0 are not affected.</p> <p>Exploitation requires one of the following:</p> <ul>
<li>The attacker is an authenticated and authorized user of the Camunda Orchestration Cluster REST API 8.9+ who has the privilege to invoke the Evaluate Expression API. The authorization requires:<!-- -->
<ul>
<li>Permission granted to user or client (directly or via role)</li> 
<li>Resource type: <code>EXPRESSION</code></li> 
<li>Permission: <code>EVALUATE</code></li> 
<li>By default, this permission is granted as part of the admin role</li> 
</ul> 
</li> 
<li>The attacker is an authenticated and authorized user who has the privilege to deploy BPMN or DMN to the Camunda Orchestration Cluster:<!-- -->
<ul>
<li>Prior to 8.8: API access (gRPC or REST)</li> 
<li>Starting 8.8: via gRPC or REST</li> 
<li>The authorization requires:<!-- -->
<ul>
<li>Permission granted to user or client (directly or via role)</li> 
<li>Resource type: <code>Resource</code></li> 
<li>Permission: <code>CREATE</code></li> 
<li>By default, this permission is granted as part of the admin role</li> 
</ul> 
</li> 
</ul> 
</li> 
<li>The attacker is an authenticated and authorized user of Camunda Web Modeler ≤ 8.9.8 or ≤ 8.8.19</li> 
</ul> <h3 id="solution">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Orchestration Cluster 8.9.21, 8.8.39</li> 
<li>Camunda Zeebe, Operate, Tasklist 8.7.41</li> 
<li>Camunda Connectors 8.9.12, 8.8.21, 8.7.27</li> 
<li>Web Modeler Self-Managed 8.9.9, 8.8.20</li> 
</ul> <p>These releases bundle a patched FEEL engine (1.22.1, 1.21.1, 1.20.3, 1.19.6, 1.18.6, 1.17.13, 1.16.6, or 1.15.5, depending on the component). If you embed the FEEL engine directly, upgrade <code>org.camunda.feel:feel-engine</code> to the patched version of your 1.x line.</p> <p>Camunda 8 SaaS was fully remediated on September 12 and 13, 2026, ahead of this notice. All clusters across all supported versions, and Web Modeler SaaS, were updated to patched builds; no action is required on your part. Clusters that were suspended at that time receive the patched version when they resume.</p> ]]></content:encoded>
</item>
<item>
  <title>Notice 63</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-63</link>
  <guid isPermaLink="false">camunda-security-notice-63</guid>
  <pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to the following vulnerabilities in the embedded Eclipse Jetty web server:</description>
  <category>Camunda Optimize</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to the following vulnerabilities in the embedded Eclipse Jetty web server:</p> <ul>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-19203" target="_blank" rel="noopener noreferrer">CVE-2026-19203</a>, where a flaw in HTTP/1.1 chunked request parsing accepts a lone line feed (<code>LF</code>) character as a terminator in parts of chunked requests. When deployed behind an intermediary reverse proxy that requires strict <code>CRLF</code> delimiters, this discrepancy in request boundary interpretation can lead to HTTP request smuggling.</li> 
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-12611" target="_blank" rel="noopener noreferrer">CVE-2026-12611</a>, where a race condition in the HTTP/2 server implementation when handling concurrent <code>RST_STREAM</code> and <code>GOAWAY</code> frames from a client can cause write-blocked threads to never be unblocked, potentially leading to thread exhaustion and a Denial of Service. The default Camunda Optimize configuration is not exploitable; this vulnerability only applies when HTTP/2 support is explicitly enabled (<code>container.http2Enabled: true</code>).</li> 
</ul> <h3 id="how-to-determine-if-the-installation-is-affected-1">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Optimize ≤ 8.7.27</li> 
</ul> <h3 id="solution-1">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Optimize 8.7.28</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 62</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-62</link>
  <guid isPermaLink="false">camunda-security-notice-62</guid>
  <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-75140 in jsoup&apos;s
XmlTreeBuilder which could allow an attacker to exhaust JVM heap memory by supplying a deeply nested XML document (in
this case a BPMN or DM...</description>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75140" target="_blank" rel="noopener noreferrer">CVE-2026-75140</a> in <code>jsoup</code>'s
<code>XmlTreeBuilder</code> which could allow an attacker to exhaust JVM heap memory by supplying a deeply nested XML document (in
this case a BPMN or DMN diagram) with uniquely-namespaced elements.</p> <h3 id="how-to-determine-if-the-installation-is-affected-2">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Web Modeler Self-Managed ≤ 8.9.7, ≤ 8.8.18, or ≤ 8.7.25</li> 
</ul> <h3 id="solution-2">Solution</h3> <p>Camunda has provided the following releases that contain the fix:</p> <ul>
<li>Web Modeler Self-Managed 8.9.8, 8.8.19, 8.7.26</li> 
</ul> <p>The fix was deployed to Web Modeler SaaS on August 29, 2026, 10:35 CET.</p> ]]></content:encoded>
</item>
<item>
  <title>Notice 61</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-61</link>
  <guid isPermaLink="false">camunda-security-notice-61</guid>
  <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
  <description>The connector runtime resolves a secret reference (for example, {{secrets.MY_API_KEY}}) wherever that literal text appears in a connector&apos;s input, without restricting resolution to the field where the...</description>
  <category>Camunda Connectors</category>
  <content:encoded><![CDATA[<p>The connector runtime resolves a secret reference (for example, <code>{{secrets.MY_API_KEY}}</code>) wherever that literal text appears in a connector's input, without restricting resolution to the field where the reference was declared. Under the following conditions, an attacker may be able to cause a connector to resolve and disclose a secret outside its intended scope:</p> <ul>
<li>The process uses <a href="https://unsupported.docs.camunda.io/8.7/docs/components/connectors/introduction-to-connectors/">connectors</a> and <a href="https://unsupported.docs.camunda.io/8.7/docs/components/console/manage-clusters/manage-secrets/">secrets</a>.</li> 
<li>Untrusted input reaches a process variable — for example, through a user task, an inbound connector such as a webhook or email, or an API call.</li> 
<li>That process variable is passed, unsanitized, into a connector field (for example, an email body or an HTTP request field).</li> 
<li>The attacker can guess or know the name of a secret that exists in that context. This does not require knowing the secret's value, only its name.</li> 
<li>The connector's destination is one the attacker controls or can observe, or the attacker can also influence the destination itself (for example, a recipient address or URL supplied through another process variable).</li> 
</ul> <p>Severity: High (CVSS 7.5).</p> <h3 id="how-to-determine-if-the-installation-is-affected-3">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Connectors 8.1.x through 8.9.x, on Self-Managed or SaaS, with connectors and secrets configured as described above.</li> 
</ul> <h3 id="solution-3">Solution</h3> <p>Camunda has released a secret filter for the connector runtime, defaulting to <code>STRICT</code> mode. In <code>STRICT</code> mode, a connector only resolves a secret that's present for that specific field in the deployed BPMN XML, which structurally closes this vulnerability for both outbound and inbound connectors. This is a breaking change: after upgrading, a connector field that relied on resolving an undeclared secret stops resolving it. See <a href="https://unsupported.docs.camunda.io/8.7/docs/self-managed/connectors-deployment/connectors-configuration/#secret-filter">secret filter</a> for configuration details, including how to change the mode.</p> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Connectors 8.9.10, 8.8.19, 8.7.25, 8.6.28</li> 
</ul> <p>On Camunda 8 SaaS, this fix is included automatically unless you've opted out of <a href="https://unsupported.docs.camunda.io/8.7/docs/reference/auto-updates/">auto-updates</a>, in which case you'll need to update your cluster manually. You can also change the mode per cluster in <a href="https://unsupported.docs.camunda.io/8.7/docs/components/console/manage-clusters/settings/#secret-filter-mode">cluster settings</a>.</p> <p><strong>Interim mitigation</strong>:</p> <ul>
<li>Review your process deployments against the preconditions above.</li> 
<li>If a process may be affected, search its process instance variables for a secret-reference literal. An API-supported query for this (a <code>$like</code> filter on the process instance search API) is available starting with 8.8; it isn't available on 8.7.</li> 
<li>Adjust the affected process so the preconditions above no longer hold, or sanitize the process variable to remove secret-reference syntax before it reaches a connector field.<!-- -->
<ul>
<li>Sanitize the respective process variable for example by replacing <code>secrets</code> keyword: <code>= replace(emailBody, "secrets?\.", "secretx_", "i")</code></li> 
</ul> 
</li> 
<li>Rotate any secret that may have been exposed, following your organization's secret-management procedures.</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 60</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-60</link>
  <guid isPermaLink="false">camunda-security-notice-60</guid>
  <pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-71290, where the embedded httpclient5 library&apos;s asynchronous transport, used to connect to the Elasticsearch/OpenSearch secondary storage, skipped hostname v...</description>
  <category>Camunda Zeebe</category>
  <category>Camunda Tasklist</category>
  <category>Camunda Operate</category>
  <category>Camunda Optimize</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71290" target="_blank" rel="noopener noreferrer">CVE-2026-71290</a>, where the embedded <code>httpclient5</code> library's asynchronous transport, used to connect to the Elasticsearch/OpenSearch secondary storage, skipped hostname verification during the TLS handshake. An attacker positioned to intercept network traffic between the affected component and its Elasticsearch/OpenSearch backend (for example, via DNS spoofing, BGP hijacking, or a compromised host on a shared network segment) could impersonate the backend, intercept the Basic authentication credentials sent to it, read or tamper with process data (including variables and process instance data) in transit, and inject forged responses back to the application. Exploitation requires this man-in-the-middle network position; it does not require bypassing authentication on the application's own API. Camunda is not aware of any known exploitation of this vulnerability.</p> <h3 id="how-to-determine-if-the-installation-is-affected-4">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Zeebe ≤ 8.7.37</li> 
<li>Camunda Tasklist ≤ 8.7.37</li> 
<li>Camunda Operate ≤ 8.7.37</li> 
<li>Camunda Optimize ≤ 8.7.26</li> 
</ul> <h3 id="solution-4">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Zeebe 8.7.38</li> 
<li>Camunda Tasklist 8.7.38</li> 
<li>Camunda Operate 8.7.38</li> 
<li>Camunda Optimize 8.7.27</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 59</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-59</link>
  <guid isPermaLink="false">camunda-security-notice-59</guid>
  <pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate>
  <description>The version of undertow-core used by Camunda Web Modeler was affected by the following vulnerabilities which could potentially allow an attacker to perform request smuggling by exploiting flaws in the...</description>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The version of <code>undertow-core</code> used by Camunda Web Modeler was affected by the following vulnerabilities which could potentially allow an attacker to perform request smuggling by exploiting flaws in the HTTP request header parsing:</p> <ul>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28367" target="_blank" rel="noopener noreferrer">CVE-2026-28367</a></li> 
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28368" target="_blank" rel="noopener noreferrer">CVE-2026-28368</a></li> 
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28369" target="_blank" rel="noopener noreferrer">CVE-2026-28369</a></li> 
</ul> <h3 id="how-to-determine-if-the-installation-is-affected-5">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Web Modeler Self-Managed ≤ 8.8.14, or ≤ 8.7.21</li> 
</ul> <h3 id="solution-5">Solution</h3> <p>Camunda has provided the following releases that contain the fix:</p> <ul>
<li>Web Modeler Self-Managed 8.8.15, 8.7.22</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 58</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-58</link>
  <guid isPermaLink="false">camunda-security-notice-58</guid>
  <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-54399, where a flaw in the
HTTP/1.1 message parser in Apache HttpComponents Core allows a remote attacker to cause a denial of service through
memory exhaust...</description>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-54399" target="_blank" rel="noopener noreferrer">CVE-2026-54399</a>, where a flaw in the
HTTP/1.1 message parser in Apache HttpComponents Core allows a remote attacker to cause a denial of service through
memory exhaustion by sending messages with an excessive number of headers or excessively long headers.</p> <p>The vulnerable library is only used in outgoing HTTP requests from Web Modeler to the Camunda 8 Orchestration
Cluster API. To exploit the vulnerability, an attacker would need to be able to control or intercept the API responses
through a prior attack. Web Modeler's inbound HTTP requests are handled by a different library, so the vulnerable code
path is not reachable from external, untrusted client traffic.</p> <h3 id="how-to-determine-if-the-installation-is-affected-6">How to determine if the installation is affected</h3> <ul>
<li>You are using Web Modeler Self-Managed ≤ 8.9.5, ≤ 8.8.16, or ≤ 8.7.23.</li> 
</ul> <h3 id="solution-6">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Web Modeler Self-Managed 8.9.6, 8.8.17, 8.7.24</li> 
</ul> <p>The fix was deployed to Web Modeler SaaS on July 8, 2026, 08:12 CET.</p> ]]></content:encoded>
</item>
<item>
  <title>Notice 57</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-57</link>
  <guid isPermaLink="false">camunda-security-notice-57</guid>
  <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-54291, where database
connections configured with channelBinding=require can be silently downgraded from SCRAM-SHA-256-PLUS with channel
binding to plain SCR...</description>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-54291" target="_blank" rel="noopener noreferrer">CVE-2026-54291</a>, where database
connections configured with <code>channelBinding=require</code> can be silently downgraded from SCRAM-SHA-256-PLUS with channel
binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee.</p> <h3 id="how-to-determine-if-the-installation-is-affected-7">How to determine if the installation is affected</h3> <ul>
<li>You are using Web Modeler Self-Managed ≤ 8.9.5, ≤ 8.8.16, or ≤ 8.7.23.</li> 
<li><em>And</em>: You are using PostgreSQL with SCRAM authentication over SSL/TLS and <code>channelBinding=require</code>.</li> 
</ul> <h3 id="solution-7">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Web Modeler Self-Managed 8.9.6, 8.8.17, 8.7.24</li> 
</ul> <p>The fix was deployed to Web Modeler SaaS on July 8, 2026, 08:12 CET.</p> ]]></content:encoded>
</item>
<item>
  <title>Notice 56</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-56</link>
  <guid isPermaLink="false">camunda-security-notice-56</guid>
  <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-13006, an arbitrary code execution vulnerability in the logback-core library used by Camunda Optimize. An attacker who already has write access to the Logbac...</description>
  <category>Camunda Optimize</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-13006" target="_blank" rel="noopener noreferrer">CVE-2026-13006</a>, an arbitrary code execution vulnerability in the <code>logback-core</code> library used by Camunda Optimize. An attacker who already has write access to the Logback configuration file, or the ability to inject an environment variable evaluated at startup, could execute arbitrary code in the Optimize process. Exploitation also requires the Janino library on the classpath and a Logback configuration that uses conditional (<code>&lt;if&gt;</code>) processing, both of which are present in Camunda Optimize. This vulnerability is not remotely exploitable; it requires an attacker to already hold privileged local access to the deployment.</p> <h3 id="how-to-determine-if-the-installation-is-affected-8">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Optimize ≤ 8.7.24</li> 
</ul> <h3 id="solution-8">Solution</h3> <p>Camunda has provided the following release which contains the fix:</p> <ul>
<li>Camunda Optimize 8.7.25</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 55</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-55</link>
  <guid isPermaLink="false">camunda-security-notice-55</guid>
  <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-40983, where an unauthenticated attacker can send a specially crafted gRPC request to trigger uncontrolled resource consumption inside Micrometer&apos;s gRPC inst...</description>
  <category>Camunda Identity</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Tasklist</category>
  <category>Camunda Operate</category>
  <category>Camunda Optimize</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40983" target="_blank" rel="noopener noreferrer">CVE-2026-40983</a>, where an unauthenticated attacker can send a specially crafted gRPC request to trigger uncontrolled resource consumption inside Micrometer's gRPC instrumentation layer, rendering the affected component unresponsive until restarted.</p> <h3 id="how-to-determine-if-the-installation-is-affected-9">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Identity ≤ 8.9.4, ≤ 8.8.13, or ≤ 8.7.20</li> 
<li>Camunda Zeebe ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Tasklist ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Operate ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Optimize ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.22</li> 
</ul> <h3 id="solution-9">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Identity 8.9.5, 8.8.14, 8.7.21</li> 
<li>Camunda Zeebe 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Tasklist 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Operate 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Optimize 8.9.10, 8.8.29, 8.7.23</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 54</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-54</link>
  <guid isPermaLink="false">camunda-security-notice-54</guid>
  <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-40984, where an unauthenticated attacker can send a specially crafted HTTP request to trigger uncontrolled resource consumption inside Micrometer&apos;s HTTP inst...</description>
  <category>Camunda Identity</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Tasklist</category>
  <category>Camunda Operate</category>
  <category>Camunda Optimize</category>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40984" target="_blank" rel="noopener noreferrer">CVE-2026-40984</a>, where an unauthenticated attacker can send a specially crafted HTTP request to trigger uncontrolled resource consumption inside Micrometer's HTTP instrumentation layer, rendering the affected component unresponsive until restarted.</p> <h3 id="how-to-determine-if-the-installation-is-affected-10">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Identity ≤ 8.9.4, ≤ 8.8.13, or ≤ 8.7.20</li> 
<li>Camunda Zeebe ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Tasklist ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Operate ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Optimize ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.22</li> 
<li>Web Modeler Self-Managed ≤ 8.9.4, ≤ 8.8.15, or ≤ 8.7.22</li> 
</ul> <h3 id="solution-10">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Identity 8.9.5, 8.8.14, 8.7.21</li> 
<li>Camunda Zeebe 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Tasklist 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Operate 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Optimize 8.9.10, 8.8.29, 8.7.23</li> 
<li>Web Modeler Self-Managed 8.9.5, 8.8.16, 8.7.23</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 53</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-53</link>
  <guid isPermaLink="false">camunda-security-notice-53</guid>
  <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-11400, where a successful exploit grants the attacker elevated database privileges on Amazon Aurora PostgreSQL, potentially enabling unauthorized read/write ...</description>
  <category>Camunda Identity</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Tasklist</category>
  <category>Camunda Operate</category>
  <category>Camunda Optimize</category>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-11400" target="_blank" rel="noopener noreferrer">CVE-2026-11400</a>, where a successful exploit grants the attacker elevated database privileges on Amazon Aurora PostgreSQL, potentially enabling unauthorized read/write access to all application data stored in the database.</p> <h3 id="how-to-determine-if-the-installation-is-affected-11">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Identity ≤ 8.9.4</li> 
<li>Camunda Zeebe ≤ 8.9.10</li> 
<li>Camunda Tasklist ≤ 8.9.10</li> 
<li>Camunda Operate ≤ 8.9.10</li> 
<li>Camunda Optimize ≤ 8.9.10</li> 
<li>Web Modeler Self-Managed ≤ 8.9.4, ≤ 8.8.15, or ≤ 8.7.22</li> 
</ul> <p>And your deployment is running on Amazon Aurora PostgreSQL with the AWS Advanced JDBC Wrapper configured to use the GlobalDatabasePlugin (for example, by setting <code>wrapperPlugins=globaldb</code> or equivalent in the JDBC connection URL). This is not the default Camunda configuration.</p> <h3 id="solution-11">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Identity 8.9.5</li> 
<li>Camunda Zeebe 8.9.11</li> 
<li>Camunda Tasklist 8.9.11</li> 
<li>Camunda Operate 8.9.11</li> 
<li>Camunda Optimize 8.9.11</li> 
<li>Web Modeler Self-Managed 8.9.5, 8.8.16, 8.7.23</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 52</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-52</link>
  <guid isPermaLink="false">camunda-security-notice-52</guid>
  <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-47691, where an attacker controlling a subdomain&apos;s name server can provide crafted NS records to poison the DNS cache for parent domains, potentially redirec...</description>
  <category>Camunda Zeebe</category>
  <category>Camunda Tasklist</category>
  <category>Camunda Operate</category>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47691" target="_blank" rel="noopener noreferrer">CVE-2026-47691</a>, where an attacker controlling a subdomain's name server can provide crafted NS records to poison the DNS cache for parent domains, potentially redirecting users to malicious servers and leading to information disclosure or integrity compromise.</p> <h3 id="how-to-determine-if-the-installation-is-affected-12">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Zeebe ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Tasklist ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Operate ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Web Modeler Self-Managed ≤ 8.9.4, ≤ 8.8.15, or ≤ 8.7.22</li> 
</ul> <h3 id="solution-12">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Zeebe 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Tasklist 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Operate 8.9.10, 8.8.29, 8.7.34</li> 
<li>Web Modeler Self-Managed 8.9.5, 8.8.16, 8.7.23</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 51</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-51</link>
  <guid isPermaLink="false">camunda-security-notice-51</guid>
  <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-45674, where a remote attacker can achieve information disclosure or data manipulation by crafting malicious DNS responses.</description>
  <category>Camunda Zeebe</category>
  <category>Camunda Tasklist</category>
  <category>Camunda Operate</category>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45674" target="_blank" rel="noopener noreferrer">CVE-2026-45674</a>, where a remote attacker can achieve information disclosure or data manipulation by crafting malicious DNS responses.</p> <h3 id="how-to-determine-if-the-installation-is-affected-13">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Zeebe ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Tasklist ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Operate ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Web Modeler Self-Managed ≤ 8.9.4, ≤ 8.8.15, or ≤ 8.7.22</li> 
</ul> <h3 id="solution-13">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Zeebe 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Tasklist 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Operate 8.9.10, 8.8.29, 8.7.34</li> 
<li>Web Modeler Self-Managed 8.9.5, 8.8.16, 8.7.23</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 50</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-50</link>
  <guid isPermaLink="false">camunda-security-notice-50</guid>
  <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-41842, where an attacker could send requests that are slow to resolve, keeping HTTP connections busy and potentially causing a Denial of Service. This is a D...</description>
  <category>Camunda Identity</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Tasklist</category>
  <category>Camunda Operate</category>
  <category>Camunda Optimize</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41842" target="_blank" rel="noopener noreferrer">CVE-2026-41842</a>, where an attacker could send requests that are slow to resolve, keeping HTTP connections busy and potentially causing a Denial of Service. This is a Denial of Service vulnerability in Spring MVC and WebFlux static resource resolution. The default Camunda configuration is not exploitable; the vulnerability requires both versioned resource resolution to be enabled (for example, by setting <code>spring.web.resources.chain.strategy.content.enabled=true</code>) and static resources to be served from the filesystem (for example, by setting <code>spring.web.resources.static-locations=file:/...</code>), neither of which is present in the default configuration.</p> <h3 id="how-to-determine-if-the-installation-is-affected-14">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Identity ≤ 8.9.4, ≤ 8.8.13, or ≤ 8.7.20</li> 
<li>Camunda Zeebe ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Tasklist ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Operate ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Optimize ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.22</li> 
</ul> <p>And your deployment has versioned resource resolution enabled and static resources served from the filesystem.</p> <h3 id="solution-14">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Identity 8.9.5, 8.8.14, 8.7.21</li> 
<li>Camunda Zeebe 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Tasklist 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Operate 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Optimize 8.9.10, 8.8.29, 8.7.23</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 49</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-49</link>
  <guid isPermaLink="false">camunda-security-notice-49</guid>
  <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-41841, where an attacker could gain access to a protected static resource if a resource with the same name had previously been resolved from a publicly acces...</description>
  <category>Camunda Identity</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Tasklist</category>
  <category>Camunda Operate</category>
  <category>Camunda Optimize</category>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41841" target="_blank" rel="noopener noreferrer">CVE-2026-41841</a>, where an attacker could gain access to a protected static resource if a resource with the same name had previously been resolved from a publicly accessible handler and cached server-side. This is an information disclosure vulnerability in Spring MVC and WebFlux static resource handling. The default Camunda configuration is not exploitable; the vulnerability requires server-side resource-chain caching to be enabled (for example, by setting <code>spring.web.resources.chain.cache=true</code>) and at least one resource handler that serves authentication-protected assets, neither of which is present in the default configuration.</p> <h3 id="how-to-determine-if-the-installation-is-affected-15">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Identity ≤ 8.9.4, ≤ 8.8.13, or ≤ 8.7.20</li> 
<li>Camunda Zeebe ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Tasklist ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Operate ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.33</li> 
<li>Camunda Optimize ≤ 8.9.9, ≤ 8.8.28, or ≤ 8.7.22</li> 
<li>Camunda Web Modeler ≤ 8.9.4, ≤ 8.8.15, or ≤ 8.7.22</li> 
</ul> <p>And your deployment has server-side resource-chain caching enabled with at least one access-controlled resource handler configured.</p> <h3 id="solution-15">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Identity 8.9.5, 8.8.14, 8.7.21</li> 
<li>Camunda Zeebe 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Tasklist 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Operate 8.9.10, 8.8.29, 8.7.34</li> 
<li>Camunda Optimize 8.9.10, 8.8.29, 8.7.23</li> 
<li>Camunda Web Modeler 8.9.5, 8.8.16, 8.7.23</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 48</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-48</link>
  <guid isPermaLink="false">camunda-security-notice-48</guid>
  <pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-42198, where an attacker with the privileges to impersonate or perform a man-in-the-middle (MITM) attack on the PostgreSQL server can force the JDBC driver t...</description>
  <category>Camunda Identity</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Tasklist</category>
  <category>Camunda Operate</category>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42198" target="_blank" rel="noopener noreferrer">CVE-2026-42198</a>, where an attacker with the privileges to impersonate or perform a man-in-the-middle (MITM) attack on the PostgreSQL server can force the JDBC driver to perform SCRAM authentication with a very large iteration count. This can lead to high CPU usage inside the SCRAM PBKDF2 computation before authentication can fail. Web Modeler and Identity are affected by this CVE when run with their default configuration. Zeebe, Operate, and Tasklist are only affected in a self-managed setup when running the application with RDBMS as secondary storage with a PostgreSQL server configured as the endpoint.</p> <h3 id="how-to-determine-if-the-installation-is-affected-16">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Identity ≤ 8.9.2, ≤ 8.8.11, or ≤ 8.7.18</li> 
<li>Camunda Zeebe ≤ 8.9.2, ≤ 8.8.23, or ≤ 8.7.28</li> 
<li>Camunda Tasklist ≤ 8.9.2, ≤ 8.8.23, or ≤ 8.7.28</li> 
<li>Camunda Operate ≤ 8.9.2, ≤ 8.8.23, or ≤ 8.7.28</li> 
<li>Camunda Web Modeler ≤ 8.9.2, ≤ 8.8.13, or ≤ 8.7.20</li> 
</ul> <h3 id="solution-16">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Identity 8.9.3, 8.8.12, 8.7.19</li> 
<li>Camunda Zeebe 8.9.3, 8.8.24, 8.7.29</li> 
<li>Camunda Tasklist 8.9.3, 8.8.24, 8.7.29</li> 
<li>Camunda Operate 8.9.3, 8.8.24, 8.7.29</li> 
<li>Camunda Web Modeler 8.9.3, 8.8.14, 8.7.21</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 47</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-47</link>
  <guid isPermaLink="false">camunda-security-notice-47</guid>
  <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-40973, where a local attacker could take control of the embedded Spring Boot ApplicationTemp directory. If server.servlet.session.persistent is set to true, ...</description>
  <category>Camunda Identity</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Tasklist</category>
  <category>Camunda Operate</category>
  <category>Camunda Optimize</category>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40973" target="_blank" rel="noopener noreferrer">CVE-2026-40973</a>, where a local attacker could take control of the embedded Spring Boot <code>ApplicationTemp</code> directory. If <code>server.servlet.session.persistent</code> is set to <code>true</code>, this could allow session hijacking or arbitrary code execution. Default Camunda 8 deployments are not affected.</p> <h3 id="how-to-determine-if-the-installation-is-affected-17">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Identity ≤ 8.9.1, ≤ 8.8.11, or ≤ 8.7.18</li> 
<li>Camunda Zeebe ≤ 8.9.1, ≤ 8.8.23, or ≤ 8.7.28</li> 
<li>Camunda Tasklist ≤ 8.9.1, ≤ 8.8.23, or ≤ 8.7.28</li> 
<li>Camunda Operate ≤ 8.9.1, ≤ 8.8.23, or ≤ 8.7.28</li> 
<li>Camunda Optimize ≤ 8.9.1, ≤ 8.8.8, or ≤ 8.7.20</li> 
<li>Camunda Web Modeler ≤ 8.9.1, ≤ 8.8.13, or ≤ 8.7.20</li> 
</ul> <h3 id="solution-17">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Identity 8.9.2, 8.8.12, 8.7.19</li> 
<li>Camunda Zeebe 8.9.2, 8.8.24, 8.7.29</li> 
<li>Camunda Tasklist 8.9.2, 8.8.24, 8.7.29</li> 
<li>Camunda Operate 8.9.2, 8.8.24, 8.7.29</li> 
<li>Camunda Optimize 8.9.2, 8.8.24, 8.7.21</li> 
<li>Camunda Web Modeler 8.9.2, 8.8.14, 8.7.21</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 46</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-46</link>
  <guid isPermaLink="false">camunda-security-notice-46</guid>
  <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
  <description>The version of axios used by Camunda Web Modeler was affected by CVE-2026-42264, a prototype pollution vulnerability in the HTTP adapter that could allow credential injection and request hijacking whe...</description>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The version of <code>axios</code> used by Camunda Web Modeler was affected by <a href="https://github.com/advisories/GHSA-q8qp-cvcw-x6jj" target="_blank" rel="noopener noreferrer">CVE-2026-42264</a>, a prototype pollution vulnerability in the HTTP adapter that could allow credential injection and request hijacking when <code>Object.prototype</code> is polluted by another dependency in the same process.</p> <h3 id="how-to-determine-if-the-installation-is-affected-18">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Web Modeler Self-Managed ≤ 8.8.13, or ≤ 8.7.20</li> 
</ul> <h3 id="solution-18">Solution</h3> <p>Camunda has provided the following releases that contain the fix:</p> <ul>
<li>Web Modeler Self-Managed 8.8.14, 8.7.21</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 45</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-45</link>
  <guid isPermaLink="false">camunda-security-notice-45</guid>
  <pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-5588, where the PKIX CompositeVerifier in the embedded Bouncy Castle cryptography library could accept an empty signature sequence as valid, weakening certif...</description>
  <category>Camunda Tasklist</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Operate</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5588" target="_blank" rel="noopener noreferrer">CVE-2026-5588</a>, where the PKIX CompositeVerifier in the embedded Bouncy Castle cryptography library could accept an empty signature sequence as valid, weakening certificate signature verification and potentially allowing acceptance of improperly signed certificates.</p> <h3 id="how-to-determine-if-the-installation-is-affected-19">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Tasklist 8.9.0, ≤ 8.8.22, or ≤ 8.7.27</li> 
<li>Camunda Zeebe 8.9.0, ≤ 8.8.22, or ≤ 8.7.27</li> 
<li>Camunda Operate 8.9.0, ≤ 8.8.22, or ≤ 8.7.27</li> 
</ul> <h3 id="solution-19">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Tasklist 8.9.1, 8.8.23, 8.7.28</li> 
<li>Camunda Zeebe 8.9.1, 8.8.23, 8.7.28</li> 
<li>Camunda Operate 8.9.1, 8.8.23, 8.7.28</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 44</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-44</link>
  <guid isPermaLink="false">camunda-security-notice-44</guid>
  <pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2025-14813, where the GOSTCTR implementation in the embedded Bouncy Castle cryptography library used an incorrect one-byte counter and could not securely encrypt ...</description>
  <category>Camunda Tasklist</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Operate</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14813" target="_blank" rel="noopener noreferrer">CVE-2025-14813</a>, where the GOSTCTR implementation in the embedded Bouncy Castle cryptography library used an incorrect one-byte counter and could not securely encrypt or decrypt more than 255 blocks, potentially compromising the confidentiality and integrity of data encrypted with this algorithm.</p> <h3 id="how-to-determine-if-the-installation-is-affected-20">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Camunda Tasklist 8.9.0, ≤ 8.8.22, or ≤ 8.7.27</li> 
<li>Camunda Zeebe 8.9.0, ≤ 8.8.22, or ≤ 8.7.27</li> 
<li>Camunda Operate 8.9.0, ≤ 8.8.22, or ≤ 8.7.27</li> 
</ul> <h3 id="solution-20">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Tasklist 8.9.1, 8.8.23, 8.7.28</li> 
<li>Camunda Zeebe 8.9.1, 8.8.23, 8.7.28</li> 
<li>Camunda Operate 8.9.1, 8.8.23, 8.7.28</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 43</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-43</link>
  <guid isPermaLink="false">camunda-security-notice-43</guid>
  <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
  <description>When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP headers will not be written. This is related to CVE-2026-22732.</description>
  <category>Management Identity</category>
  <category>Camunda Tasklist</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Operate</category>
  <category>Camunda Optimize</category>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP headers will not be written. This is related to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22732" target="_blank" rel="noopener noreferrer">CVE-2026-22732</a>.</p> <h3 id="how-to-determine-if-the-installation-is-affected-21">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Management Identity 8.7.4 - 8.7.10, 8.7.12 - 8.7.16, 8.8.0 - 8.8.2, or 8.8.5 - 8.8.9</li> 
<li>Zeebe 8.7.21 - 8.7.25</li> 
<li>Tasklist 8.7.21 - 8.7.25</li> 
<li>Operate 8.7.22 - 8.7.25</li> 
<li>Optimize 8.7.14 - 8.7.18 or 8.8.2 - 8.8.7</li> 
<li>Web Modeler Self-Managed ≤ 8.6.26, ≤ 8.7.18, or ≤ 8.8.11</li> 
</ul> <h3 id="solution-21">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Management Identity 8.7.17, 8.8.10</li> 
<li>Zeebe 8.7.26</li> 
<li>Tasklist 8.7.26</li> 
<li>Operate 8.7.26</li> 
<li>Optimize 8.7.19, 8.8.8</li> 
<li>Web Modeler Self-Managed 8.6.27, 8.7.19, 8.8.12</li> 
</ul> <p>The fix was deployed to Web Modeler SaaS on March 23, 2026, 17:26 CET.</p> ]]></content:encoded>
</item>
<item>
  <title>Notice 42</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-42</link>
  <guid isPermaLink="false">camunda-security-notice-42</guid>
  <pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate>
  <description>The application was vulnerable to CVE-2026-24734, which allowed an attacker to bypass revocation checks of client SSL certificates if a certain server configuration was used.</description>
  <category>Management Identity</category>
  <content:encoded><![CDATA[<p>The application was vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24734" target="_blank" rel="noopener noreferrer">CVE-2026-24734</a>, which allowed an attacker to bypass revocation checks of client SSL certificates if a certain server configuration was used.</p> <h3 id="how-to-determine-if-the-installation-is-affected-22">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Management Identity ≤ 8.8.7, ≤ 8.7.14, or ≤ 8.6.27</li> 
</ul> <h3 id="solution-22">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Management Identity 8.8.8, 8.7.15, 8.6.28</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 41</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-41</link>
  <guid isPermaLink="false">camunda-security-notice-41</guid>
  <pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate>
  <description>The version of fast-xml-parser used by Camunda Web Modeler was affected by CVE-2026-26278, a vulnerability which could be exploited as a vector for denial of service attacks by forcing the parser to d...</description>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The version of <code>fast-xml-parser</code> used by Camunda Web Modeler was affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26278" target="_blank" rel="noopener noreferrer">CVE-2026-26278</a>, a vulnerability which could be exploited as a vector for denial of service attacks by forcing the parser to do an unlimited amount of entity expansions.</p> <h3 id="how-to-determine-if-the-installation-is-affected-23">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Web Modeler Self-Managed ≤ 8.8.8, ≤ 8.7.16, or ≤ 8.6.25</li> 
</ul> <h3 id="solution-23">Solution</h3> <p>Camunda has provided the following releases that contain the fix:</p> <ul>
<li>Web Modeler Self-Managed 8.8.9, 8.7.17, 8.6.26</li> 
</ul> <p>This issue does not affect Web Modeler SaaS.</p> ]]></content:encoded>
</item>
<item>
  <title>Notice 40</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-40</link>
  <guid isPermaLink="false">camunda-security-notice-40</guid>
  <pubDate>Mon, 23 Feb 2026 00:00:00 GMT</pubDate>
  <description>The version of Tomcat used by the Diagram Converter Webapp was affected by:</description>
  <category>C7 to C8 Migration Tooling</category>
  <content:encoded><![CDATA[<p>The version of Tomcat used by the Diagram Converter Webapp was affected by:</p> <ul>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66614" target="_blank" rel="noopener noreferrer">CVE-2025-66614</a></li> 
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24734" target="_blank" rel="noopener noreferrer">CVE-2026-24734</a></li> 
</ul> <h3 id="how-to-determine-if-the-installation-is-affected-24">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>C7 to C8 Migration Tooling 0.2.0 <strong>AND</strong></li> 
<li>the Diagram Converter Webapp</li> 
</ul> <h3 id="solution-24">Solution</h3> <p>Camunda has released the <strong>C7 to C8 Migration Tooling 0.2.1</strong>, which includes the fix.</p> ]]></content:encoded>
</item>
<item>
  <title>Notice 39</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-39</link>
  <guid isPermaLink="false">camunda-security-notice-39</guid>
  <pubDate>Tue, 10 Feb 2026 00:00:00 GMT</pubDate>
  <description>The version of fast-xml-parser used by Camunda Web Modeler was affected by CVE-2026-25128, a RangeError vulnerability that could crash any application that processes untrusted XML input.</description>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The version of <code>fast-xml-parser</code> used by Camunda Web Modeler was affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25128" target="_blank" rel="noopener noreferrer">CVE-2026-25128</a>, a RangeError vulnerability that could crash any application that processes untrusted XML input.</p> <h3 id="how-to-determine-if-the-installation-is-affected-25">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Web Modeler Self-Managed ≤ 8.8.6, ≤ 8.7.15, or ≤ 8.6.24</li> 
</ul> <h3 id="solution-25">Solution</h3> <p>Camunda has provided the following releases that contain the fix:</p> <ul>
<li>Web Modeler Self-Managed 8.8.7, 8.7.16, 8.6.25</li> 
</ul> <p>The fix was deployed to Web Modeler SaaS on February 2, 2026, 15:15 CET.</p> ]]></content:encoded>
</item>
<item>
  <title>Notice 38</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-38</link>
  <guid isPermaLink="false">camunda-security-notice-38</guid>
  <pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate>
  <description>The version of qs used by Camunda Web Modeler was affected by CVE-2025-15284, an improper input validation vulnerability that allows HTTP DoS.</description>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The version of <code>qs</code> used by Camunda Web Modeler was affected by CVE-2025-15284, an improper input validation vulnerability that allows HTTP DoS.</p> <h3 id="how-to-determine-if-the-installation-is-affected-26">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Web Modeler Self-Managed ≤ 8.8.4, ≤ 8.7.14, or ≤ 8.6.23</li> 
</ul> <h3 id="solution-26">Solution</h3> <p>Camunda has provided the following releases that contain the fix:</p> <ul>
<li>Web Modeler Self-Managed 8.8.5, 8.7.15, 8.6.24</li> 
</ul> <p>The fix was deployed to Web Modeler SaaS on January 7, 2026, 13:45 CET.</p> ]]></content:encoded>
</item>
<item>
  <title>Notice 37</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-37</link>
  <guid isPermaLink="false">camunda-security-notice-37</guid>
  <pubDate>Fri, 12 Dec 2025 00:00:00 GMT</pubDate>
  <description>The application is vulnerable to CVE-2025-12183, which allows remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.</description>
  <category>Camunda Tasklist</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Operate</category>
  <content:encoded><![CDATA[<p>The application is vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12183" target="_blank" rel="noopener noreferrer">CVE-2025-12183</a>, which allows remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.</p> <h3 id="how-to-determine-if-the-installation-is-affected-27">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Tasklist/Zeebe/Operate ≤ 8.8.6, ≤ 8.7.20, or ≤ 8.6.32</li> 
</ul> <h3 id="solution-27">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Tasklist/Zeebe/Operate 8.8.7, 8.7.21, 8.6.33</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 36</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-36</link>
  <guid isPermaLink="false">camunda-security-notice-36</guid>
  <pubDate>Wed, 03 Dec 2025 00:00:00 GMT</pubDate>
  <description>The application is vulnerable to CVE-2025-53066, which allows an unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalV...</description>
  <category>Management Identity</category>
  <content:encoded><![CDATA[<p>The application is vulnerable to <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53066" target="_blank" rel="noopener noreferrer">CVE-2025-53066</a>, which allows an unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data.</p> <h3 id="how-to-determine-if-the-installation-is-affected-28">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Management Identity ≤ 8.8.2, ≤ 8.7.10, or ≤ 8.6.22</li> 
</ul> <h3 id="solution-28">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Management Identity 8.8.3, 8.7.11, 8.6.23</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 35</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-35</link>
  <guid isPermaLink="false">camunda-security-notice-35</guid>
  <pubDate>Wed, 26 Nov 2025 00:00:00 GMT</pubDate>
  <description>The embedded JDBC driver for Amazon Aurora PostgreSQL (software.amazon.jdbc:aws-advanced-jdbc-wrapper) was affected by
CVE-2025-12967, which may allow for privilege escalation to the rds_superuser rol...</description>
  <category>Camunda Web Modeler Self-Managed</category>
  <category>Camunda Management Identity</category>
  <content:encoded><![CDATA[<p>The embedded JDBC driver for Amazon Aurora PostgreSQL (<code>software.amazon.jdbc:aws-advanced-jdbc-wrapper</code>) was affected by
<a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12967" target="_blank" rel="noopener noreferrer">CVE-2025-12967</a>, which may allow for privilege escalation to the <code>rds_superuser</code> role.
A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.</p> <h3 id="how-to-determine-if-the-installation-is-affected-29">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Web Modeler Self-Managed ≤ 8.8.2, ≤ 8.7.12, or ≤ 8.6.21 with Amazon Aurora PostgreSQL</li> 
<li>Management Identity ≤ 8.8.1, ≤ 8.7.9, or ≤ 8.6.21 with Amazon Aurora PostgreSQL</li> 
</ul> <h3 id="solution-29">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Web Modeler Self-Managed 8.8.3, 8.7.13, 8.6.22</li> 
<li>Management Identity 8.8.2, 8.7.10, 8.6.22</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 34</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-34</link>
  <guid isPermaLink="false">camunda-security-notice-34</guid>
  <pubDate>Tue, 11 Nov 2025 00:00:00 GMT</pubDate>
  <description>The version of the MSSQL JDBC driver com.microsoft.sqlserver:mssql-jdbc used by Web Modeler was affected by CVE-2025-59250, which allows improper input validation that could enable an attacker to perf...</description>
  <category>Camunda Web Modeler Self-Managed</category>
  <content:encoded><![CDATA[<p>The version of the MSSQL JDBC driver <code>com.microsoft.sqlserver:mssql-jdbc</code> used by Web Modeler was affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59250" target="_blank" rel="noopener noreferrer">CVE-2025-59250</a>, which allows improper input validation that could enable an attacker to perform spoofing over a network.</p> <h3 id="how-to-determine-if-the-installation-is-affected-30">How to determine if the installation is affected</h3> <p>You are using Web Modeler Self-Managed version &lt;= 8.8.1 and Microsoft SQL Server as database vendor.</p> <h3 id="solution-30">Solution</h3> <p>Camunda has provided the following release which contains the fix:</p> <ul>
<li>Web Modeler Self-Managed 8.8.2</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 33</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-33</link>
  <guid isPermaLink="false">camunda-security-notice-33</guid>
  <pubDate>Wed, 22 Oct 2025 00:00:00 GMT</pubDate>
  <description>A bug in signal broadcast command processing allowed unauthorized users to trigger signal start events or signal intermediate catch events in certain process definitions without the required create or...</description>
  <category>Camunda Orchestration Cluster</category>
  <content:encoded><![CDATA[<p>A bug in signal broadcast command processing allowed unauthorized users to trigger signal start events or signal intermediate catch events in certain process definitions without the required create or update permissions.</p> <p>This did not allow users to access process definitions of other tenants, or leak any information about these process instances back to the unauthorized users.</p> <h3 id="how-to-determine-if-the-installation-is-affected-31">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Orchestration Cluster 8.8.0</li> 
</ul> <h3 id="solution-31">Solution</h3> <p>Camunda has provided the following release which contains the fix:</p> <ul>
<li>Orchestration Cluster 8.8.1</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 32</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-32</link>
  <guid isPermaLink="false">camunda-security-notice-32</guid>
  <pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate>
  <description>The embedded Apache Tomcat was affected by CVE-2025-48989 which made Tomcat vulnerable to the MadeYouReset attack.</description>
  <category>Camunda Identity</category>
  <content:encoded><![CDATA[<p>The embedded Apache Tomcat was affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48989" target="_blank" rel="noopener noreferrer">CVE-2025-48989</a> which made Tomcat vulnerable to the MadeYouReset attack.</p> <h3 id="how-to-determine-if-the-installation-is-affected-32">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Identity 8.7.0 - 8.7.4 or 8.7.6 - 8.7.7</li> 
</ul> <h3 id="solution-32">Solution</h3> <p>Camunda has provided the following release which contains the fix:</p> <ul>
<li>Identity 8.7.8</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 31</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-31</link>
  <guid isPermaLink="false">camunda-security-notice-31</guid>
  <pubDate>Thu, 16 Oct 2025 00:00:00 GMT</pubDate>
  <description>The embedded Undertow web server was affected by CVE-2025-9784,
a flaw where malformed client requests can trigger server-side stream resets without incrementing abuse counters.</description>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The embedded Undertow web server was affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9784" target="_blank" rel="noopener noreferrer">CVE-2025-9784</a>,
a flaw where malformed client requests can trigger server-side stream resets without incrementing abuse counters.</p> <p>This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by
repeatedly causing server-side stream aborts and could be exploited to cause a denial of service (DoS).</p> <h3 id="how-to-determine-if-the-installation-is-affected-33">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Web Modeler Self-Managed 8.8.0, ≤ 8.7.10, or ≤ 8.6.19</li> 
</ul> <h3 id="solution-33">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Web Modeler Self-Managed 8.8.1, 8.7.11, 8.6.20</li> 
</ul> <p>The fix was deployed to Web Modeler SaaS on October 14, 2025, 14:26 CET.</p> ]]></content:encoded>
</item>
<item>
  <title>Notice 30</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-30</link>
  <guid isPermaLink="false">camunda-security-notice-30</guid>
  <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
  <description>The embedded Netty was affected by CVE-2025-58056, an HTTP request
smuggling vulnerability in Netty. Incorrect parsing of chunked transfer encoding could allow attackers to craft
malicious requests th...</description>
  <category>Camunda Tasklist</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Operate</category>
  <category>Camunda Optimize</category>
  <category>Camunda Identity</category>
  <content:encoded><![CDATA[<p>The embedded Netty was affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58056" target="_blank" rel="noopener noreferrer">CVE-2025-58056</a>, an HTTP request
smuggling vulnerability in Netty. Incorrect parsing of chunked transfer encoding could allow attackers to craft
malicious requests that are interpreted inconsistently by proxies and Netty.</p> <h3 id="how-to-determine-if-the-installation-is-affected-34">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Tasklist 8.7.0 - 8.7.12 or 8.5.0 - 8.5.22</li> 
<li>Zeebe 8.7.0 - 8.7.12 or 8.5.0 - 8.5.24</li> 
<li>Operate 8.7.0 - 8.7.12 or 8.5.0 - 8.5.20</li> 
<li>Optimize 8.7.0 - 8.7.9 or 8.6.0 - 8.6.16</li> 
<li>Identity 8.7.0 - 8.7.6 or 8.6.0 - 8.6.19 or 8.5.0 - 8.5.21</li> 
</ul> <h3 id="solution-34">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Tasklist 8.7.13, 8.5.23</li> 
<li>Zeebe 8.7.13, 8.5.25</li> 
<li>Operate 8.7.13, 8.5.21</li> 
<li>Optimize 8.7.10, 8.6.17</li> 
<li>Identity 8.7.7, 8.6.20, 8.5.22</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 29</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-29</link>
  <guid isPermaLink="false">camunda-security-notice-29</guid>
  <pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate>
  <description>Zeebe may be affected by CVE-2024-41996, which allows remote attackers to trigger expensive server-side DHE modular-exponentiation calculations, potentially causing asymmetric resource consumption and...</description>
  <category>Camunda Zeebe</category>
  <content:encoded><![CDATA[<p>Zeebe may be affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41996" target="_blank" rel="noopener noreferrer">CVE-2024-41996</a>, which allows remote attackers to trigger expensive server-side DHE modular-exponentiation calculations, potentially causing asymmetric resource consumption and DoS attacks.</p> <h3 id="how-to-determine-if-the-installation-is-affected-35">How to determine if the installation is affected</h3> <p>You are potentially affected if you have configured Zeebe to accept DHE or ECDHE cipher suites through the <code>server.ssl.ciphers</code> property or <code>SERVER_SSL_CIPHERS</code> environment variable.</p> <p>Default Zeebe installations are not affected.</p> <h3 id="solution-35">Solution</h3> <p>Configure the <code>server.ssl.ciphers</code> property or <code>SERVER_SSL_CIPHERS</code> environment variable to exclude DHE and ECDHE cipher suites. For example:</p> <div><div><pre tabindex="0"><code><span><span>server.ssl.ciphers=TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA</span><br></span></code></pre></div> </div> <p>There is no known mitigation other than disabling the use of DHE and ECDHE cipher suites.</p> ]]></content:encoded>
</item>
<item>
  <title>Notice 28</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-28</link>
  <guid isPermaLink="false">camunda-security-notice-28</guid>
  <pubDate>Tue, 09 Sep 2025 00:00:00 GMT</pubDate>
  <description>Optimize was affected by CVE-2025-5115, which allows a remote attacker to repeatedly send malformed HTTP/2 frames that exhaust a Jetty server’s CPU and memory, causing a denial-of-service.</description>
  <category>Camunda Optimize</category>
  <content:encoded><![CDATA[<p>Optimize was affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5115" target="_blank" rel="noopener noreferrer">CVE-2025-5115</a>, which allows a remote attacker to repeatedly send malformed HTTP/2 frames that exhaust a Jetty server’s CPU and memory, causing a denial-of-service.</p> <h3 id="how-to-determine-if-the-installation-is-affected-36">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Optimize 8.7.0 - 8.7.8 or 8.6.0 - 8.6.15</li> 
</ul> <h3 id="solution-36">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Optimize 8.7.9, 8.6.16</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 27</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-27</link>
  <guid isPermaLink="false">camunda-security-notice-27</guid>
  <pubDate>Wed, 27 Aug 2025 00:00:00 GMT</pubDate>
  <description>Optimize&apos;s email functionality was affected by CVE-2025-7962, which allowed for SMTP injection by providing forged email recipient addresses that could lead to malicious content being sent to arbitrar...</description>
  <category>Camunda Optimize</category>
  <content:encoded><![CDATA[<p>Optimize's email functionality was affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7962" target="_blank" rel="noopener noreferrer">CVE-2025-7962</a>, which allowed for SMTP injection by providing forged email recipient addresses that could lead to malicious content being sent to arbitrary recipients.</p> <h3 id="how-to-determine-if-the-installation-is-affected-37">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Optimize 8.7.0 - 8.7.7 or 8.6.0 - 8.6.14</li> 
</ul> <h3 id="solution-37">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Optimize 8.7.8, 8.6.15</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 26</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-26</link>
  <guid isPermaLink="false">camunda-security-notice-26</guid>
  <pubDate>Wed, 27 Aug 2025 00:00:00 GMT</pubDate>
  <description>Optimize was affected by CVE-2025-53864 which allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion.</description>
  <category>Camunda Optimize</category>
  <content:encoded><![CDATA[<p>Optimize was affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53864" target="_blank" rel="noopener noreferrer">CVE-2025-53864</a> which allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion.</p> <h3 id="how-to-determine-if-the-installation-is-affected-38">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Optimize 8.7.0 - 8.7.7 or 8.6.0 - 8.6.14</li> 
</ul> <h3 id="solution-38">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Optimize 8.7.8, 8.6.15</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 25</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-25</link>
  <guid isPermaLink="false">camunda-security-notice-25</guid>
  <pubDate>Wed, 27 Aug 2025 00:00:00 GMT</pubDate>
  <description>The embedded Apache Tomcat was affected by CVE-2025-48989 which made Tomcat vulnerable to the MadeYouReset attack.</description>
  <category>Camunda Tasklist</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Operate</category>
  <category>Camunda Optimize</category>
  <content:encoded><![CDATA[<p>The embedded Apache Tomcat was affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48989" target="_blank" rel="noopener noreferrer">CVE-2025-48989</a> which made Tomcat vulnerable to the MadeYouReset attack.</p> <h3 id="how-to-determine-if-the-installation-is-affected-39">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Tasklist 8.7.0 - 8.7.10 or 8.6.0 - 8.6.24 or 8.5.0 - 8.5.20</li> 
<li>Zeebe 8.7.0 - 8.7.10 or 8.6.0 - 8.6.24</li> 
<li>Operate 8.7.0 - 8.7.10 or 8.6.0 - 8.6.24 or 8.5.0 - 8.5.18</li> 
<li>Optimize 8.7.0 - 8.7.7 or 8.6.0 - 8.6.14</li> 
</ul> <h3 id="solution-39">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Tasklist 8.7.11, 8.6.25, 8.5.21</li> 
<li>Zeebe 8.7.11, 8.6.25</li> 
<li>Operate 8.7.11, 8.6.25, 8.5.19</li> 
<li>Optimize 8.7.8, 8.6.15</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 24</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-24</link>
  <guid isPermaLink="false">camunda-security-notice-24</guid>
  <pubDate>Wed, 27 Aug 2025 00:00:00 GMT</pubDate>
  <description>The embedded Netty was affected by CVE-2025-55163 which allows malformed HTTP/2 control frames usage that results in resource exhaustion and distributed denial of service.</description>
  <category>Camunda Tasklist</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Operate</category>
  <category>Camunda Identity</category>
  <category>Camunda Optimize</category>
  <content:encoded><![CDATA[<p>The embedded Netty was affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55163" target="_blank" rel="noopener noreferrer">CVE-2025-55163</a> which allows malformed HTTP/2 control frames usage that results in resource exhaustion and distributed denial of service.</p> <h3 id="how-to-determine-if-the-installation-is-affected-40">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Tasklist 8.7.0 - 8.7.10 or 8.6.0 - 8.6.24 or 8.5.0 - 8.5.20</li> 
<li>Zeebe 8.7.0 - 8.7.10 or 8.6.0 - 8.6.24 or 8.5.0 - 8.5.22</li> 
<li>Operate 8.7.0 - 8.7.10 or 8.6.0 - 8.6.24 or 8.5.0 - 8.5.18</li> 
<li>Identity 8.7.0 - 8.7.5 or 8.6.0 - 8.6.18 or 8.5.0 - 8.5.19</li> 
<li>Optimize 8.7.0 - 8.7.7 or 8.6.0 - 8.6.14</li> 
</ul> <h3 id="solution-40">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Tasklist 8.7.11, 8.6.25, 8.5.21</li> 
<li>Zeebe 8.7.11, 8.6.25, 8.5.23</li> 
<li>Operate 8.7.11, 8.6.25, 8.5.19</li> 
<li>Identity 8.7.6, 8.6.19, 8.5.20</li> 
<li>Optimize 8.7.8, 8.6.15</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 23</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-23</link>
  <guid isPermaLink="false">camunda-security-notice-23</guid>
  <pubDate>Thu, 31 Jul 2025 00:00:00 GMT</pubDate>
  <description>The embedded Spring Boot Tomcat was affected by CVE-2025-53506 which allowed for uncontrolled resource consumption that could be used to exhaust system resources in a potential DoS (denial of service)...</description>
  <category>Camunda Tasklist</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Operate</category>
  <category>Camunda Identity</category>
  <category>Camunda Optimize</category>
  <content:encoded><![CDATA[<p>The embedded Spring Boot Tomcat was affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53506" target="_blank" rel="noopener noreferrer">CVE-2025-53506</a> which allowed for uncontrolled resource consumption that could be used to exhaust system resources in a potential DoS (denial of service) attack.</p> <h3 id="how-to-determine-if-the-installation-is-affected-41">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Tasklist 8.7.0 - 8.7.8 or 8.6.0 - 8.6.22 or 8.5.0 - 8.5.18</li> 
<li>Zeebe 8.7.0 - 8.7.8 or 8.6.0 - 8.6.22</li> 
<li>Operate 8.7.0 - 8.7.8 or 8.6.0 - 8.6.22 or 8.5.0 - 8.5.16</li> 
<li>Identity 8.7.0 - 8.7.4 or 8.6.0 - 8.6.17 or 8.5.0 - 8.5.18</li> 
<li>Optimize 8.7.0 - 8.7.6 or 8.6.0 - 8.6.12</li> 
</ul> <h3 id="solution-41">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Tasklist 8.7.9, 8.6.23, 8.5.19</li> 
<li>Zeebe 8.7.9, 8.6.23</li> 
<li>Operate 8.7.9, 8.6.23, 8.5.17</li> 
<li>Identity 8.7.5, 8.6.18, 8.5.19</li> 
<li>Optimize 8.7.7, 8.6.13</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 22</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-22</link>
  <guid isPermaLink="false">camunda-security-notice-22</guid>
  <pubDate>Thu, 31 Jul 2025 00:00:00 GMT</pubDate>
  <description>Part of our RESTful API that supported multipart file uploads was affected by CVE-2025-52520, which could lead to potential DoS (denial of service) attacks.</description>
  <category>Camunda Tasklist</category>
  <category>Camunda Zeebe</category>
  <category>Camunda Operate</category>
  <content:encoded><![CDATA[<p>Part of our RESTful API that supported multipart file uploads was affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52520" target="_blank" rel="noopener noreferrer">CVE-2025-52520</a>, which could lead to potential DoS (denial of service) attacks.</p> <h3 id="how-to-determine-if-the-installation-is-affected-42">How to determine if the installation is affected</h3> <p>You are using:</p> <ul>
<li>Tasklist 8.6.0 - 8.6.22 or 8.7.0 - 8.7.8</li> 
<li>Zeebe 8.6.0 - 8.6.22 or 8.7.0 - 8.7.8</li> 
<li>Operate 8.6.0 - 8.6.22 or 8.7.0 - 8.7.8</li> 
</ul> <h3 id="solution-42">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Tasklist 8.6.22</li> 
<li>Tasklist 8.7.9</li> 
<li>Zeebe 8.6.23</li> 
<li>Zeebe 8.7.9</li> 
<li>Operate 8.6.23</li> 
<li>Operate 8.7.9</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 21</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-21</link>
  <guid isPermaLink="false">camunda-security-notice-21</guid>
  <pubDate>Wed, 18 Jun 2025 00:00:00 GMT</pubDate>
  <description>The version of org.postgresql:postgresql used by Camunda Web Modeler Self-Managed was affected by CVE-2025-49146 potentially allowing a man-in-the-middle attacker to intercept connections when the Pos...</description>
  <category>Camunda Web Modeler Self-Managed</category>
  <content:encoded><![CDATA[<p>The version of <code>org.postgresql:postgresql</code> used by Camunda Web Modeler Self-Managed was affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49146" target="_blank" rel="noopener noreferrer">CVE-2025-49146</a> potentially allowing a man-in-the-middle attacker to intercept connections when the PostgreSQL JDBC driver was configured with channel binding set to required.</p> <h3 id="how-to-determine-if-the-installation-is-affected-43">How to determine if the installation is affected</h3> <p>You are using Camunda Web Modeler Self-Managed version 8.6.0 - 8.6.12, or 8.7.0 - 8.7.3.</p> <h3 id="solution-43">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Web Modeler Self-Managed 8.6.12</li> 
<li>Camunda Web Modeler Self-Managed 8.7.3</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 20</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-20</link>
  <guid isPermaLink="false">camunda-security-notice-20</guid>
  <pubDate>Tue, 17 Jun 2025 00:00:00 GMT</pubDate>
  <description>Camunda Optimize was affected by a vulnerability that allowed an attacker to gain improper access to Optimize data by using a modified JWT (JSON Web Token).</description>
  <category>Camunda Optimize</category>
  <content:encoded><![CDATA[<p>Camunda Optimize was affected by a vulnerability that allowed an attacker to gain improper access to Optimize data by using a modified JWT (JSON Web Token).</p> <h3 id="how-to-determine-if-the-installation-is-affected-44">How to determine if the installation is affected</h3> <p>You are using Camunda Optimize ≤ 8.6.9 or ≤ 8.7.2.</p> <h3 id="solution-44">Solution</h3> <p>Camunda has provided the following release which contains a fix:</p> <ul>
<li><a href="https://github.com/camunda/camunda/releases/tag/8.6.10-optimize" target="_blank" rel="noopener noreferrer">Camunda Optimize 8.6.10</a></li> 
<li><a href="https://github.com/camunda/camunda/releases/tag/8.7.3-optimize" target="_blank" rel="noopener noreferrer">Camunda Optimize 8.7.3</a></li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 19</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-19</link>
  <guid isPermaLink="false">camunda-security-notice-19</guid>
  <pubDate>Wed, 21 May 2025 00:00:00 GMT</pubDate>
  <description>The version of nodejs used by Camunda Web Modeler was affected by CVE-2025-23166 potentially allowing an adversary to remotely crash the Node.js runtime.</description>
  <category>Camunda Web Modeler</category>
  <content:encoded><![CDATA[<p>The version of <code>nodejs</code> used by Camunda Web Modeler was affected by <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23166" target="_blank" rel="noopener noreferrer">CVE-2025-23166</a> potentially allowing an adversary to remotely crash the Node.js runtime.</p> <h3 id="how-to-determine-if-the-installation-is-affected-45">How to determine if the installation is affected</h3> <p>You are using Camunda Web Modeler Self-Managed version ≤ 8.4.17, ≤ 8.5.18, ≤ 8.6.10, or ≤ 8.7.1.</p> <h3 id="solution-45">Solution</h3> <p>Camunda has provided the following releases which contain the fix:</p> <ul>
<li>Camunda Web Modeler Self-Managed 8.4.18</li> 
<li>Camunda Web Modeler Self-Managed 8.5.19</li> 
<li>Camunda Web Modeler Self-Managed 8.6.11</li> 
<li>Camunda Web Modeler Self-Managed 8.7.2</li> 
</ul> <p>The fix was deployed to Web Modeler SaaS on May 19, 2025, 15:10 CET.</p> ]]></content:encoded>
</item>
<item>
  <title>Notice 18</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-18</link>
  <guid isPermaLink="false">camunda-security-notice-18</guid>
  <pubDate>Tue, 08 Apr 2025 00:00:00 GMT</pubDate>
  <description>Camunda Optimize was affected by a vulnerability that allowed an attacker to modify a JWT (JSON Web Token) so that they would be given improper access to Optimize.</description>
  <category>Camunda Optimize</category>
  <content:encoded><![CDATA[<p>Camunda Optimize was affected by a vulnerability that allowed an attacker to modify a JWT (JSON Web Token) so that they would be given improper access to Optimize.</p> <h3 id="how-to-determine-if-the-installation-is-affected-46">How to determine if the installation is affected</h3> <p>You are using Camunda Optimize ≤ 8.4.15, ≤ 8.5.12, ≤ 8.6.6, ≤ 8.7.0, ≤ 3.11.20, ≤ 3.12.15, ≤ 3.13.12, ≤ 3.14.3, ≤ 3.15.1.</p> <h3 id="solution-46">Solution</h3> <p>Camunda has provided the following release which contains a fix:</p> <ul>
<li>Camunda Optimize 8.4.16, 8.5.13, 8.6.7, 8.7.0, 3.12.16, 3.13.13, 3.14.4, 3.15.2</li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 17</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-17</link>
  <guid isPermaLink="false">camunda-security-notice-17</guid>
  <pubDate>Tue, 08 Apr 2025 00:00:00 GMT</pubDate>
  <description>When parsing unknown fields in the Protobuf Java Lite and Full library, a maliciously crafted message can cause a StackOverflow error and lead to a
program crash.</description>
  <category>Camunda Zeebe</category>
  <content:encoded><![CDATA[<p>When parsing unknown fields in the Protobuf Java Lite and Full library, a maliciously crafted message can cause a StackOverflow error and lead to a
program crash.</p> <ul>
<li>As Zeebe makes extensive use of Protobuf, this could lead to denial-of-service (DoS) issues on the server side.</li> 
<li>This issue allows an attacker to send specific payloads that will always result in <code>StackOverflowException</code>. This could lead to gateway performance issues and affect system availability.</li> 
<li>Although the gateway will not crash, it will spend more time working on these requests. An attacker could use this opportunity to slow it down and make it unusable by sending a large number of requests within a short time frame.</li> 
</ul> <p>No data is leaked, lost, or corrupted. This issue only affects application availability.</p> <p><a href="https://github.com/advisories/GHSA-735f-pc8j-v9w8" target="_blank" rel="noopener noreferrer">Learn more about this CVE at the GitHub Advisory Database</a>.</p> <h3 id="how-to-determine-if-the-installation-is-affected-47">How to determine if the installation is affected</h3> <p>You are using Camunda Zeebe 8.6.11.</p> <h3 id="solution-47">Solution</h3> <p>Camunda has provided the following release which contains a fix:</p> <ul>
<li><a href="https://github.com/camunda/camunda/releases/tag/8.6.13" target="_blank" rel="noopener noreferrer">Camunda Zeebe 8.6.13</a></li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 16</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-16</link>
  <guid isPermaLink="false">camunda-security-notice-16</guid>
  <pubDate>Fri, 14 Mar 2025 00:00:00 GMT</pubDate>
  <description>Some Camunda Zeebe versions were affected by a vulnerability that allowed a malicious attacker to craft network packets that could crash the gateway.</description>
  <category>Camunda Zeebe</category>
  <content:encoded><![CDATA[<p>Some Camunda Zeebe versions were affected by a vulnerability that allowed a malicious attacker to craft network packets that could crash the gateway.</p> <h3 id="how-to-determine-if-the-installation-is-affected-48">How to determine if the installation is affected</h3> <p>You are using Camunda Zeebe 8.6.0 - 8.6.11</p> <h3 id="solution-48">Solution</h3> <p>Camunda has provided the following release which contains a fix:</p> <ul>
<li><a href="https://github.com/camunda/camunda/releases/tag/8.6.12" target="_blank" rel="noopener noreferrer">Camunda Zeebe 8.6.12</a></li> 
</ul> ]]></content:encoded>
</item>
<item>
  <title>Notice 15</title>
  <link>https://unsupported.docs.camunda.io/8.7/docs/reference/notices/#notice-15</link>
  <guid isPermaLink="false">camunda-security-notice-15</guid>
  <pubDate>Tue, 11 Mar 2025 00:00:00 GMT</pubDate>
  <description>Some Camunda Optimize versions were affected by a vulnerability that allowed a malicious attacker to craft Camunda URLs that could execute JavaScript code.</description>
  <category>Camunda Optimize</category>
  <content:encoded><![CDATA[<p>Some Camunda Optimize versions were affected by a vulnerability that allowed a malicious attacker to craft Camunda URLs that could execute JavaScript code.</p> <h3 id="how-to-determine-if-the-installation-is-affected-49">How to determine if the installation is affected</h3> <p>You are using Camunda Optimize ≤ 8.6.5.</p> <h3 id="solution-49">Solution</h3> <p>Camunda has provided the following release which contains a fix:</p> <ul>
<li><a href="https://github.com/camunda/camunda/releases/tag/8.6.6-optimize" target="_blank" rel="noopener noreferrer">Camunda Optimize 8.6.6</a></li> 
</ul> ]]></content:encoded>
</item>
</channel>
</rss>
