CVE-2024-27348: Apache HugeGraph-Server Improper Access Control Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-09-18. EPSS: 99.2% chance of exploitation in the next 30 days.

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.

Affected products

  • Apache Hugegraph: from 1.0.0, before 1.3.0 (fixed in 1.3.0)

Published 2024-04-22. Last modified 2026-06-17.