← Vulnerability feed

Vulnerability record · CVE-2024-43441 · published 24 December 2024

CVE-2024-43441: Apache HugeGraph-Server authentication bypass via assumed-immutable data

Apache · Hugegraph

Apache HugeGraph-Server versions 1.0.0 through before 1.5.0 contain an authentication bypass caused by reliance on assumed-immutable data (CWE-302). A remote, unauthenticated attacker can bypass authentication logic, which matters because the server is a database backend that should not be reachable without credentials. The vendor recommends upgrading to 1.5.0, which fixes the issue.

9.8 CVSS 3.1 Critical EPSS 69% · top 0.7% CWE-302 · CWE-302
9.8CVSS 3.1 base score
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or user interaction, and high EPSS make this a top remediation priority despite no KEV listing.

What it is

Apache HugeGraph-Server versions 1.0.0 through before 1.5.0 contain an authentication bypass caused by reliance on assumed-immutable data (CWE-302). A remote, unauthenticated attacker can bypass authentication logic, which matters because the server is a database backend that should not be reachable without credentials. The vendor recommends upgrading to 1.5.0, which fixes the issue.

Impact

An attacker gains unauthenticated access to functionality that should require authentication, with the CVSS vector indicating high confidentiality, integrity and availability impact. In practice this can mean full read and write access to graph data and potential disruption of the service.

Attack surface

Reachable over the network via the HugeGraph-Server API or service interface, per the AV:N vector. No authentication and no user interaction are required (PR:N, UI:N), so any exposed instance is directly reachable.

Exploitation

Not listed in CISA KEV and no public exploit reference is tagged in the advisory, but EPSS is high at roughly 0.69 (99th percentile), indicating elevated likelihood of exploitation activity. Treat as a realistic target despite the absence of confirmed in-the-wild reporting.

What to do

  • Upgrade Apache HugeGraph-Server to version 1.5.0 or later, which the vendor states fixes the issue.
  • If immediate upgrade is not possible, restrict network access to HugeGraph-Server ports to trusted hosts only and place it behind an authenticated gateway.
  • Do not expose HugeGraph-Server directly to the internet; bind to internal interfaces and enforce firewall rules.
  • Audit HugeGraph-Server logs and data for unauthorized access or modification during the exposure window.
  • Monitor the Apache mailing list advisory for any further guidance or updated fixed versions.

Detection

  • Review HugeGraph-Server access logs for API requests that succeed without valid authentication or session tokens.
  • Alert on requests to authentication or admin endpoints from unexpected source IPs or with anomalous parameters.
  • Baseline normal client behavior and flag new source addresses, unusual query patterns, or bulk data reads/writes.
  • Correlate HugeGraph-Server process activity with outbound connections or file changes that suggest post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-43441 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2024-43441), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.