← Vulnerability feed

Vulnerability record · CVE-2024-27348 · published 22 April 2024

CVE-2024-27348: Apache HugeGraph-Server improper access control leads to remote code execution

Apache · Hugegraph

Apache HugeGraph-Server versions from 1.0.0 before 1.3.0 on Java 8 and Java 11 contain an improper access control flaw that allows remote command execution. The vendor fix is upgrading to 1.3.0 with Java 11 and enabling the authentication system, indicating the default configuration is exposed. It matters because a network-reachable, unauthenticated flaw in a data platform gives attackers direct code execution.

9.8 CVSS 3.1 Critical CISA KEV since 18 Sep 2024 EPSS 99% · top 0.1% CWE-284 · Improper access control
9.8CVSS 3.1 base score
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
8References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8 unauthenticated network RCE, CISA KEV listing and EPSS near 1.0 make this an urgent patch-first issue.

What it is

Apache HugeGraph-Server versions from 1.0.0 before 1.3.0 on Java 8 and Java 11 contain an improper access control flaw that allows remote command execution. The vendor fix is upgrading to 1.3.0 with Java 11 and enabling the authentication system, indicating the default configuration is exposed. It matters because a network-reachable, unauthenticated flaw in a data platform gives attackers direct code execution.

Impact

An unauthenticated remote attacker can execute arbitrary commands on the HugeGraph-Server host, leading to full compromise of the server and any data or credentials it can reach.

Attack surface

Reachable over the network via the HugeGraph-Server service; the CVSS vector shows no privileges and no user interaction required. The vendor's recommendation to enable the Auth system implies deployments without authentication are the exposed ones.

Exploitation

Listed in CISA KEV with a 2024-10-09 remediation due date, and EPSS is 0.9921 (99.9th percentile), so exploitation is expected and observed. A third-party reference is tagged Exploit, but the record does not name a specific public exploit tool.

What to do

  • Upgrade Apache HugeGraph-Server to 1.3.0 or later and run it on Java 11 as the vendor advises.
  • Enable the HugeGraph authentication system so the server is not reachable unauthenticated.
  • Restrict network access to the HugeGraph-Server port to trusted hosts only until patching is complete.
  • If the upgrade cannot be applied promptly, follow CISA KEV guidance and discontinue use of the product until mitigations are available.
  • Audit existing deployments for signs of prior compromise before and after remediation.

Detection

  • Monitor HugeGraph-Server logs and process activity for unexpected child processes or shell commands spawned by the Java service.
  • Alert on inbound connections to the HugeGraph-Server port from untrusted or unexpected source addresses.
  • Hunt for anomalous outbound connections or file writes originating from the HugeGraph-Server host.
  • Verify authentication is enabled and check for requests reaching the server without credentials.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-27348 to the Known Exploited Vulnerabilities catalog on 18 September 2024 as "Apache HugeGraph-Server Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 9 October 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-27348 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2024-27348), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.