← Vulnerability feed

Vulnerability record · CVE-2024-7314 · published 2 August 2024

CVE-2024-7314: AJ-Report authentication bypass via ;swagger-ui path allows RCE

AAnji Plus · Report

anji-plus AJ-Report contains an authentication bypass where appending ";swagger-ui" to HTTP requests skips authentication. Because the bypass exposes functionality that leads to arbitrary Java execution, an unauthenticated remote attacker can run code on the server. Exploitation evidence was observed in the wild by Shadowserver on 2025-02-05.

9.8 CVSS 3.1 Critical EPSS 52% · top 1.1% CWE-288 · Authentication bypass via alternate path
9.8CVSS 3.1 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 3 tagged exploit
17 Jun 2026Last modified by NVD

Description

anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to HTTP requests to bypass authentication and execute arbitrary Java on the victim server. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with high EPSS and observed in-the-wild exploitation.

What it is

anji-plus AJ-Report contains an authentication bypass where appending ";swagger-ui" to HTTP requests skips authentication. Because the bypass exposes functionality that leads to arbitrary Java execution, an unauthenticated remote attacker can run code on the server. Exploitation evidence was observed in the wild by Shadowserver on 2025-02-05.

Impact

An attacker gains unauthenticated remote code execution on the victim server, giving full control of the application process and its data. This can lead to data theft, lateral movement, and full host compromise.

Attack surface

Reachable over the network via HTTP requests with a crafted ";swagger-ui" path suffix; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is 0.5175 (98.9th percentile) and multiple references are tagged Exploit, with in-the-wild exploitation evidence reported by Shadowserver.

What to do

  • Apply the vendor patch or upgrade AJ-Report to a fixed release as soon as one is available.
  • If no patch exists, restrict network access to AJ-Report to trusted management networks only.
  • Block or reject requests containing ";swagger-ui" path segments at the reverse proxy or WAF.
  • Disable or remove the Swagger UI endpoint if it is not required.
  • Rotate credentials and secrets on any host suspected of compromise.

Detection

  • Search web logs for requests containing ";swagger-ui" in the URI path.
  • Alert on unexpected Java child processes or outbound connections from the AJ-Report server.
  • Monitor for anomalous POST requests to AJ-Report endpoints from unauthenticated sources.
  • Review host telemetry for new files or scheduled tasks created by the AJ-Report service account.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-7314 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-20079Cisco Secure Firewall Management Center authentication bypass to rootCisco Secure Firewall Management Center (FMC) Software contains an authentication bypass caused by an improper system process created at boot time. A…KEVEPSS 88%analysed9.3CVE-2026-19490Citrix NetScaler ADC and Gateway authentication bypass via alternate pathNetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel (CWE-288). The flaw is remotely reachable witho…KEVEPSS 7.0%analysed8.2CVE-2026-18556N-able N-central authentication bypass via alternate pathN-able N-central contains an authentication bypass (CWE-288) that lets an attacker reach protected functionality through an alternate path or channel…KEVEPSS 7.9%analysed8.2CVE-2026-18577N-able N-central incomplete patch enables auth bypass and account takeoverAn incomplete fix for CVE-2026-18556 leaves an alternate-path authentication bypass in N-able N-central through version 2026.3.1. Because the origina…KEVEPSS 15%analysed7.5CVE-2026-1603Ivanti Endpoint Manager authentication bypass leaks stored credentialsIvanti Endpoint Manager before 2024 SU5 contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker reach a func…KEVEPSS 88%analysed9.8CVE-2026-24858Fortinet FortiCloud SSO authentication bypass across registered devicesA CWE-288 authentication bypass in Fortinet FortiAnalyzer, FortiManager, FortiNAC-F, FortiOS, FortiProxy and FortiWeb lets an attacker with a FortiCl…KEVEPSS 86%analysed9.3CVE-2026-23760SmarterMail password reset API authentication bypassSmarterMail builds prior to 9511 expose a force-reset-password endpoint that accepts anonymous requests and does not verify the current password or a…KEVEPSS 97%analysed9.2CVE-2025-34026Versa Concerto authentication bypass in Traefik proxy exposes admin endpointsVersa Concerto's Traefik reverse proxy configuration contains an authentication bypass (CWE-288) that lets an unauthenticated attacker reach administ…KEVEPSS 82%analysed

Source: NIST National Vulnerability Database (record CVE-2024-7314), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.