PT-2026-24715 · Neo4J · Neo4J Enterprise Edition

CVE-2026-1497

·

Publicado

2026-03-11

·

Atualizado

2026-08-28

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Neo4j Enterprise edition versions prior to 2026.02 Neo4j Enterprise edition versions prior to 5.26.22
Description An incorrect resolution of namespaces in composite databases in Neo4j Enterprise edition can lead to a scenario where an administrator unintentionally grants access to local databases or remote aliases. Specifically, when an administrator attempts to grant a user access to a remote database constituent using the format 'namespace.name', access is inadvertently granted to any local database or remote alias named 'name'. If a database or alias with that name does not exist at the time the command is executed, the privileges will be applied if it is created in the future.
Recommendations Update Neo4j Enterprise edition to version 2026.02 or later. Update Neo4j Enterprise edition to version 5.26.22 or later.

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-NEO4J-2026-1497
BIT-NEO4J-ENTERPRISE-2026-1497
CVE-2026-1497

Produtos afetados

Neo4J Enterprise Edition