<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>TigerGraph - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/tigergraph/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 15:12:26 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/tigergraph/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in TigerGraph Community Edition via Default Credentials</title><link>https://feed.craftedsignal.io/briefs/2026-10-tigergraph-rce/</link><pubDate>Thu, 01 Oct 2026 15:12:26 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-tigergraph-rce/</guid><description>TigerGraph Community Edition 4.2.4 contains a remote code execution chain initiated by hard-coded default credentials, enabling an arbitrary file write that allows for SSH key injection.</description><content:encoded><![CDATA[<p>TigerGraph Community Edition 4.2.4 is susceptible to a full remote code execution chain due to multiple architectural security flaws. The vulnerability begins with the use of hard-coded default credentials (tigergraph:tigergraph) on the GUI administration port (14240), which lacks enforcement for password rotation. An attacker who authenticates can access the GUI's reverse-proxy to the GSQL service on port 8123 to install a malicious query capable of writing arbitrary files to the underlying Linux host. Because the REST++ interface on port 9000 fails to authenticate requests, this file-write primitive can be triggered by unauthenticated remote users. By targeting the '/home/tigergraph/.ssh/authorized_keys' file, an attacker can append a controlled public key, subsequently gaining persistent shell access as the 'tigergraph' OS user via SSH.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker authenticates to the TigerGraph GUI on port 14240 using the default hard-coded credentials 'tigergraph:tigergraph'.</li>
<li>Attacker leverages the GUI's proxy to the internal GSQL service (port 8123) to install a custom GSQL query, defined with a FILE parameter that provides an unrestricted arbitrary file write primitive.</li>
<li>Attacker triggers the newly installed GSQL query via the REST++ interface on port 9000, which operates without requiring authentication.</li>
<li>Attacker submits a request to the REST++ endpoint, specifying the destination path as '/home/tigergraph/.ssh/authorized_keys'.</li>
<li>The server writes the attacker-supplied public key into the 'authorized_keys' file on the host filesystem.</li>
<li>Attacker initiates an SSH connection to port 22 of the target, authenticating using the private key corresponding to the public key injected in the previous step.</li>
<li>Attacker successfully gains an interactive shell session as the 'tigergraph' user, enabling further lateral movement or data exfiltration.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated remote attacker to gain persistent unauthorized access to the host operating system with the privileges of the 'tigergraph' service account (UID 1001). This impact includes complete control over the TigerGraph database environment, the ability to read or modify sensitive database information, and the potential for lateral movement within the network from the compromised host.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately change the default 'tigergraph' administrative password on all exposed instances.</li>
<li>Restrict network access to the administration GUI (port 14240), the REST++ interface (port 9000), and the SSH port (22) to authorized management subnets only.</li>
<li>Review the directory permissions for the '/home/tigergraph/.ssh/' directory to ensure only the owner can modify 'authorized_keys'.</li>
<li>Monitor access logs on port 14240 for credential-based logins and port 9000 for unexpected REST++ query executions.</li>
<li>Disable SSH public key authentication for the 'tigergraph' user if it is not explicitly required for administrative operations.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>remote-code-execution</category><category>default-credentials</category><category>privilege-escalation</category></item></channel></rss>