Junglewise Threat Intelligence

CVE-2026-1524: Neo4j Enterprise Edition incorrect authorization in SSO implementation

CVE-2026-1524 · Severity: info · CVSS 9.8 · Published 2026-03-11

Executive brief

A security flaw in Neo4j Enterprise Edition's Single Sign-On (SSO) system can allow users to gain higher access privileges than intended. This occurs when the database is configured to use multiple identity providers, causing the system to mistakenly grant administrative or elevated permissions from a provider that was only supposed to verify a user's identity. If exploited, an unauthorized user could gain full control over the database and its sensitive information.

Technical details

An incorrect authorization vulnerability exists in Neo4j Enterprise Edition's SSO implementation. When an administrator configures multiple OIDC providers or plugins where at least one is set for authorization and another is set for authentication-only, the system may erroneously use the authentication-only provider to grant authorization permissions. If the authentication-only provider contains groups with higher privileges than the intended authorization provider, a user can achieve privilege escalation. This issue affects versions prior to 2026.02 and 5.26.22. The vulnerability is reachable over the network without specific user interaction, provided the specific multi-provider configuration is active.

Affected products

  • Neo4j Neo4j Enterprise Edition prior to 2026.02, prior to 5.26.22

Timeline

  • 2026-03-11: disclosed: Initial disclosure by Neo4j
  • 2026-03-11: advisory: Vendor advisory published
  • 2026-05-22: other: NVD analysis and CPE assignment

References