PT-2026-24727 · Neo4J · Neo4J Enterprise Edition

CVE-2026-1524

·

Publicado

2026-03-11

·

Atualizado

2026-05-29

CVSS v4.0

2.1

Baixa

VetorAV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Green
Name of the Vulnerable Software and Affected Versions Neo4j Enterprise edition versions prior to 2026.02 Neo4j Enterprise edition versions prior to 5.26.22
Description An issue in the Single Sign-On (SSO) implementation in Neo4j Enterprise edition can lead to unauthorized access. This occurs when a Neo4j administrator configures two or more OpenID Connect (OIDC) providers, with at least one configured for authorization and one configured for authentication only. If the authentication-only provider contains groups with higher privileges than the intended authorization provider, it can incorrectly provide authorization capabilities. Prior to the fix, a plugin configured for only authentication or authorization could erroneously provide both capabilities.
Recommendations Upgrade to version 2026.02. Upgrade to version 5.26.22.

Exploit

Correção

Improper Authentication

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-NEO4J-2026-1524
CVE-2026-1524

Produtos afetados

Neo4J Enterprise Edition