CVE-2023-22951
HIGHTigerGraph Enterprise Free Edition 3.x - Unauthenticated Privilege Escalation via Exposed REST API Token
Title source: llmDescription
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal systems use. This token can be read from the configuration file. Using this token on the REST API provides an attacker with anonymous admin-level privileges on all REST API endpoints.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://neo4j.com/security/cve-2023-22951/
Scores
CVSS v3
8.8
EPSS
0.0083
EPSS Percentile
52.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-276
Status
published
Products (2)
tigergraph/cloud
tigergraph/tigergraph_enterprise
3.7.0 (2 CPE variants)
Published
Apr 13, 2023
Tracked Since
Feb 18, 2026