@neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-level @authentication rule is also present on the same operation type. When both a type-level @authentication (on Query/Mutation) and a field-level @authentication (on a root custom-resolver field within that type) are declared, only the type-level rule is evaluated and the field-level rule is silently discarded. As a result a stricter per-field requirement — such as an admin-role JWT claim (jwt: { roles_INCLUDES: "admin" }) — is never checked, and any client that satisfies the coarser type-level requirement can invoke the more-restricted field. No token forgery is involved: a legitimately issued, correctly signed non-admin token (e.g. roles: ["user"]) is sufficient.
{
"cna_assigner": "Neo4j",
"cwe_ids": [
"CWE-639"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19869.json"
}{
"extracted_events": [
{
"introduced": "7.0.0"
},
{
"fixed": "7.6.0"
},
{
"introduced": "5.2.0"
},
{
"fixed": "5.12.15"
},
{
"introduced": "6.0.0"
},
{
"last_affected": "6.6.4"
}
],
"source": "AFFECTED_FIELD"
}