Excessive Caching Vulnerability in Neo4j Enterprise Edition
CVE-2026-1471
2.1LOW
What is CVE-2026-1471?
Excessive caching of authentication context in Neo4j Enterprise Edition can lead to a situation where authenticated users erroneously inherit the authentication context of the first user who logged in following a server restart. This vulnerability primarily affects specific non-default configurations of Single Sign-On (SSO) at the UserInfo endpoint. To mitigate this risk, users are advised to upgrade to versions 2026.01.4 or 5.26.22, where this vulnerability has been addressed.
Affected Version(s)
Enterprise edition 2025.01 < 2026.01.4
Enterprise edition 4.4.0 < 5.26.22
