Excessive Caching Vulnerability in Neo4j Enterprise Edition
CVE-2026-1471

2.1LOW

Key Information:

Vendor

Neo4j

Vendor
CVE Published:
11 March 2026

What is CVE-2026-1471?

Excessive caching of authentication context in Neo4j Enterprise Edition can lead to a situation where authenticated users erroneously inherit the authentication context of the first user who logged in following a server restart. This vulnerability primarily affects specific non-default configurations of Single Sign-On (SSO) at the UserInfo endpoint. To mitigate this risk, users are advised to upgrade to versions 2026.01.4 or 5.26.22, where this vulnerability has been addressed.

Affected Version(s)

Enterprise edition 2025.01 < 2026.01.4

Enterprise edition 4.4.0 < 5.26.22

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.