EXPOSURES › CVE-2024-27348
CVE-2024-27348
HIGH ⌖ ON CISA KEV · EXPLOITEDApache HugeGraph-Server allows remote arbitrary code execution via improper access control, enabling attackers to compromise graph databases used by defense systems.
Apache HugeGraph-Server contains a critical improper access control vulnerability (CVE-2024-27348) that permits remote attackers to execute arbitrary code, directly violating NIST 800-171 access control requirements. Defense contractors must immediately patch this vulnerability and audit all Apache HugeGraph deployments to prevent unauthorized code execution and data exfiltration.
Shame score — A critical RCE vulnerability in a graph database product used by defense systems was actively exploited and linked to ransomware campaigns, indicating negligent security posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.