PT-2026-24726 · Neo4J · Neo4J Enterprise Edition

Published

2026-03-11

·

Updated

2026-05-29

·

CVE-2026-1471

CVSS v4.0

2.1

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/AU:N/R:U/V:D/RE:L/U:Clear
Name of the Vulnerable Software and Affected Versions Neo4j Enterprise edition versions prior to 2026.01.4
Description Excessive caching of authentication context in Neo4j Enterprise edition allows authenticated users to inherit the context of the first user who authenticated after a restart. This issue is limited to specific, non-default configurations of Single Sign-On (SSO) utilizing the UserInfo endpoint.
Recommendations Upgrade to version 2026.01.4 or 5.26.22 to resolve the issue.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-NEO4J-2026-1471
CVE-2026-1471

Affected Products

Neo4J Enterprise Edition