Information Disclosure Vulnerability in Neo4j Enterprise Edition
CVE-2025-12738
1.3LOW
What is CVE-2025-12738?
Neo4j Enterprise Edition is susceptible to an information disclosure vulnerability that allows attackers with legitimate access to the database to infer sensitive information. This vulnerability is particularly concerning as it enables an attacker without direct read access to discern the values of properties by analyzing error messages generated during SET property attempts. To safeguard your database, it is crucial to upgrade to versions 2025.11.2 or 5.26.17, where this issue is addressed.
Affected Version(s)
Enterprise Edition 0 < 2025.11.2
Enterprise Edition 0 < 5.26.17
