BIT-neo4j-2026-1471

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/neo4j/BIT-neo4j-2026-1471.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-neo4j-2026-1471
Aliases
Published
2026-05-29T10:28:48Z
Modified
2026-09-10T16:01:44Z
Summary
Caching of authentication context
Details

Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.1.4 leads to authenticated users inheriting the context of the first user who authenticated after restart. The issue is limited to certain non-default configurations of SSO (UserInfo endpoint). We recommend upgrading to versions 2026.1.4 (or 5.26.22) where the issue is fixed.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:neo4j:neo4j:*:*:*:*:enterprise:*:*:*"
    ],
    "severity":  "Medium"
}
References

Affected packages

Bitnami / neo4j

Package

Name
neo4j
Purl
pkg:bitnami/neo4j

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.26.22
Introduced
2025.1.0
Fixed
2026.1.4

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/neo4j/BIT-neo4j-2026-1471.json"