← Advisories

Apache HugeGraph 1.7.0 Sandbox Bypass Remote Code Execution

Critical
Advisory ID
ZSL-2026-6014
Release Date
09 October 2026
Vendor
The Apache Software Foundation - https://www.apache.org
Affected Version
1.7.0 and 1.8.0-dev (master)
CVE
N/A
Tested On
GNU/Linux 7.0.12-linuxkit (aarch64), GNU/Linux 6.12.76-linuxkit (aarch64), GNU/Linux 6.8.0-88-generic (x86_64), Groovy 2.5.14, OpenJDK 11
Summary

HugeGraph is a full-stack graph system covering graph database, graph computing, and graph AI. It provides complete graph data processing capabilities from storage and real-time querying to offline analysis, and supports both Gremlin and Cypher query languages.

Description

Apache HugeGraph suffers from a remote code execution vulnerability caused by a bypass of its SecurityManager-based Gremlin execution sandbox. HugeGraph executes submitted Gremlin as Groovy and relies on a custom HugeSecurityManager to block operating-system access, but that manager only denies calls whose current thread name identifies them as Gremlin threads. By defining a class whose finalize() method runs an operating-system command and forcing garbage collection, the command executes on the JVM Finalizer thread, where the check does not apply, and the sandbox is bypassed. Because authentication is disabled in the default configuration, a remote attacker can reach the Gremlin endpoint and execute arbitrary OS commands with root privileges.

Proof of Concept
Disclosure Timeline
13.08.2026Vulnerability discovered.
18.08.2026Contact with the vendor.
19.08.2026Vendor forwards details to appropriate PMC.
08.10.2026No response from the vendor.
09.10.2026Public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
09.10.2026Initial release