Junglewise Threat Intelligence

CVE-2026-1497: Neo4j Enterprise Edition incorrect authorization in composite databases

CVE-2026-1497 · Severity: high · CVSS 7.2 · Published 2026-03-11

Executive brief

A security flaw in Neo4j Enterprise Edition's database management system can cause administrators to accidentally grant users more access than intended. When an admin tries to give a user permission to a specific remote database, the system may mistakenly grant that user access to local databases or aliases with similar names. This could lead to unauthorized users viewing or modifying sensitive data they were never supposed to reach.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Neo4j Enterprise Edition due to improper namespace resolution within composite databases. When an administrator attempts to grant privileges to a remote database constituent using the 'namespace.name' format, the system may inadvertently apply those privileges to any local database or remote alias sharing the same 'name'. This logic error also applies to future objects; if a database or alias with that name is created after the command is run, the unintended privileges will automatically take effect. The issue is specific to environments utilizing the composite database feature and is resolved in versions 5.26.22 and 2026.02.

Affected products

  • Neo4j Neo4j Enterprise Edition < 5.26.22, 2025.01.0 to < 2026.02

Timeline

  • 2026-03-11: disclosed
  • 2026-03-11: advisory

References