High severity8.8NVD Advisory· Published Apr 13, 2023· Updated Jun 17, 2026
CVE-2023-22951
CVE-2023-22951
Description
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal systems use. This token can be read from the configuration file. Using this token on the REST API provides an attacker with anonymous admin-level privileges on all REST API endpoints.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:a:tigergraph:cloud:-:*:*:*:*:*:*:*
cpe:2.3:a:tigergraph:tigergraph_enterprise:3.7.0:*:*:*:free:-:*:*+ 1 more
- cpe:2.3:a:tigergraph:tigergraph_enterprise:3.7.0:*:*:*:free:-:*:*
- cpe:2.3:a:tigergraph:tigergraph_enterprise:3.7.0:*:*:*:free:docker:*:*
- TigerGraph/Enterprise Free Editiondescription
- Range: 3.x
Patches
Vulnerability mechanics
References
2- neo4j.com/security/cve-2023-22951/nvdExploitThird Party Advisory
- dev.tigergraph.com/forum/c/tg-community/announcements/35nvdProduct
News mentions
0No linked articles in our index yet.