{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/tigergraph-community-edition-4.2.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TigerGraph Community Edition (4.2.4)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","default-credentials","privilege-escalation"],"_cs_type":"threat","_cs_vendors":["TigerGraph"],"content_html":"\u003cp\u003eTigerGraph Community Edition 4.2.4 is susceptible to a full remote code execution chain due to multiple architectural security flaws. The vulnerability begins with the use of hard-coded default credentials (tigergraph:tigergraph) on the GUI administration port (14240), which lacks enforcement for password rotation. An attacker who authenticates can access the GUI's reverse-proxy to the GSQL service on port 8123 to install a malicious query capable of writing arbitrary files to the underlying Linux host. Because the REST++ interface on port 9000 fails to authenticate requests, this file-write primitive can be triggered by unauthenticated remote users. By targeting the '/home/tigergraph/.ssh/authorized_keys' file, an attacker can append a controlled public key, subsequently gaining persistent shell access as the 'tigergraph' OS user via SSH.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the TigerGraph GUI on port 14240 using the default hard-coded credentials 'tigergraph:tigergraph'.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the GUI's proxy to the internal GSQL service (port 8123) to install a custom GSQL query, defined with a FILE parameter that provides an unrestricted arbitrary file write primitive.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the newly installed GSQL query via the REST++ interface on port 9000, which operates without requiring authentication.\u003c/li\u003e\n\u003cli\u003eAttacker submits a request to the REST++ endpoint, specifying the destination path as '/home/tigergraph/.ssh/authorized_keys'.\u003c/li\u003e\n\u003cli\u003eThe server writes the attacker-supplied public key into the 'authorized_keys' file on the host filesystem.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an SSH connection to port 22 of the target, authenticating using the private key corresponding to the public key injected in the previous step.\u003c/li\u003e\n\u003cli\u003eAttacker successfully gains an interactive shell session as the 'tigergraph' user, enabling further lateral movement or data exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to gain persistent unauthorized access to the host operating system with the privileges of the 'tigergraph' service account (UID 1001). This impact includes complete control over the TigerGraph database environment, the ability to read or modify sensitive database information, and the potential for lateral movement within the network from the compromised host.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately change the default 'tigergraph' administrative password on all exposed instances.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the administration GUI (port 14240), the REST++ interface (port 9000), and the SSH port (22) to authorized management subnets only.\u003c/li\u003e\n\u003cli\u003eReview the directory permissions for the '/home/tigergraph/.ssh/' directory to ensure only the owner can modify 'authorized_keys'.\u003c/li\u003e\n\u003cli\u003eMonitor access logs on port 14240 for credential-based logins and port 9000 for unexpected REST++ query executions.\u003c/li\u003e\n\u003cli\u003eDisable SSH public key authentication for the 'tigergraph' user if it is not explicitly required for administrative operations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T15:12:26Z","date_published":"2026-10-01T15:12:26Z","id":"https://feed.craftedsignal.io/briefs/2026-10-tigergraph-rce/","summary":"TigerGraph Community Edition 4.2.4 contains a remote code execution chain initiated by hard-coded default credentials, enabling an arbitrary file write that allows for SSH key injection.","title":"Remote Code Execution in TigerGraph Community Edition via Default Credentials","url":"https://feed.craftedsignal.io/briefs/2026-10-tigergraph-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - TigerGraph Community Edition (4.2.4)","version":"https://jsonfeed.org/version/1.1"}