Vulnerability record · CVE-2024-27348 · published 22 April 2024
CVE-2024-27348: Apache HugeGraph-Server improper access control leads to remote code execution
Apache · Hugegraph
Apache HugeGraph-Server versions from 1.0.0 before 1.3.0 on Java 8 and Java 11 contain an improper access control flaw that allows remote command execution. The vendor fix is upgrading to 1.3.0 with Java 11 and enabling the authentication system, indicating the default configuration is exposed. It matters because a network-reachable, unauthenticated flaw in a data platform gives attackers direct code execution.
Description
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 unauthenticated network RCE, CISA KEV listing and EPSS near 1.0 make this an urgent patch-first issue.
What it is
Apache HugeGraph-Server versions from 1.0.0 before 1.3.0 on Java 8 and Java 11 contain an improper access control flaw that allows remote command execution. The vendor fix is upgrading to 1.3.0 with Java 11 and enabling the authentication system, indicating the default configuration is exposed. It matters because a network-reachable, unauthenticated flaw in a data platform gives attackers direct code execution.
Impact
An unauthenticated remote attacker can execute arbitrary commands on the HugeGraph-Server host, leading to full compromise of the server and any data or credentials it can reach.
Attack surface
Reachable over the network via the HugeGraph-Server service; the CVSS vector shows no privileges and no user interaction required. The vendor's recommendation to enable the Auth system implies deployments without authentication are the exposed ones.
Exploitation
Listed in CISA KEV with a 2024-10-09 remediation due date, and EPSS is 0.9921 (99.9th percentile), so exploitation is expected and observed. A third-party reference is tagged Exploit, but the record does not name a specific public exploit tool.
What to do
- Upgrade Apache HugeGraph-Server to 1.3.0 or later and run it on Java 11 as the vendor advises.
- Enable the HugeGraph authentication system so the server is not reachable unauthenticated.
- Restrict network access to the HugeGraph-Server port to trusted hosts only until patching is complete.
- If the upgrade cannot be applied promptly, follow CISA KEV guidance and discontinue use of the product until mitigations are available.
- Audit existing deployments for signs of prior compromise before and after remediation.
Detection
- Monitor HugeGraph-Server logs and process activity for unexpected child processes or shell commands spawned by the Java service.
- Alert on inbound connections to the HugeGraph-Server port from untrusted or unexpected source addresses.
- Hunt for anomalous outbound connections or file writes originating from the HugeGraph-Server host.
- Verify authentication is enabled and check for requests reaching the server without credentials.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-27348 to the Known Exploited Vulnerabilities catalog on 18 September 2024 as "Apache HugeGraph-Server Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 9 October 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2024/04/22/3 | Mailing ListThird Party Advisory |
| https://hugegraph.apache.org/docs/config/config-authentication/#configure-user-authentication | Product |
| https://lists.apache.org/thread/nx6g6htyhpgtzsocybm242781o8w5kq9 | Mailing ListVendor Advisory |
| http://www.openwall.com/lists/oss-security/2024/04/22/3 | Mailing ListThird Party Advisory |
| https://hugegraph.apache.org/docs/config/config-authentication/#configure-user-authentication | Product |
| https://lists.apache.org/thread/nx6g6htyhpgtzsocybm242781o8w5kq9 | Mailing ListVendor Advisory |
| https://www.vicarius.io/vsociety/posts/remote-code-execution-vulnerability-in-apache-hugegraph-server-cve-2024-27348 | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-27348 | Third Party AdvisoryUS Government Resource |
Track CVE-2024-27348 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-27348), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.