CVE-2024-27348
Apache HugeGraph-Server: Command execution in gremlin
- Published
- Apr 22, 2024
- Updated
- Oct 21, 2025
- Assigning CNA
- apache
- Evidence observed
- Sep 18, 2024
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.
Sources
7- CVE-2024-27348-HugeGraph-RCEExploit
Advanced PoC exploit for CVE-2024-27348, achieving reliable RCE in Apache HugeGraph via sandbox bypass and non-blind command execution.
- CVE-2024-27348Exploit
Proof-of-concept exploit for unauthenticated remote code execution in Apache HugeGraph Server via Groovy injection. Supports single and multi-target command execution.
- CVE-2024-27348Exploit
This is a repository for Apache HugeGraph Remote Code Execution vulnerability(CVE-2024-27348))
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.