PT-2026-24726 · Neo4J · Neo4J Enterprise Edition
Publicado
2026-03-11
·
Atualizado
2026-05-29
·
CVE-2026-1471
CVSS v4.0
2.1
Baixa
| Vetor | AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/AU:N/R:U/V:D/RE:L/U:Clear |
Name of the Vulnerable Software and Affected Versions
Neo4j Enterprise edition versions prior to 2026.01.4
Description
Excessive caching of authentication context in Neo4j Enterprise edition allows authenticated users to inherit the context of the first user who authenticated after a restart. This issue is limited to specific, non-default configurations of Single Sign-On (SSO) utilizing the
UserInfo endpoint.Recommendations
Upgrade to version 2026.01.4 or 5.26.22 to resolve the issue.
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Neo4J Enterprise Edition