PT-2026-24726 · Neo4J · Neo4J Enterprise Edition
Published
2026-03-11
·
Updated
2026-05-29
·
CVE-2026-1471
CVSS v4.0
2.1
Low
| Vector | AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/AU:N/R:U/V:D/RE:L/U:Clear |
Name of the Vulnerable Software and Affected Versions
Neo4j Enterprise edition versions prior to 2026.01.4
Description
Excessive caching of authentication context in Neo4j Enterprise edition allows authenticated users to inherit the context of the first user who authenticated after a restart. This issue is limited to specific, non-default configurations of Single Sign-On (SSO) utilizing the
UserInfo endpoint.Recommendations
Upgrade to version 2026.01.4 or 5.26.22 to resolve the issue.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Neo4J Enterprise Edition