Namespace Access Issue in Neo4j Enterprise Edition
CVE-2026-1497

2LOW

Key Information:

Vendor

Neo4j

Vendor
CVE Published:
11 March 2026

What is CVE-2026-1497?

In the Neo4j Enterprise Edition, a flaw in the resolution of namespaces within composite databases allows an administrator to inadvertently grant access permissions to unintended local databases or remote aliases. If an admin attempts to provide access to a specific database constituent identified as 'namespace.name', they may unknowingly permit access to any local database or remote alias named 'name'. If such a database or alias does not exist at the time of the command execution, the privileges will extend to any future creation of a database or alias that matches this name convention.

Affected Version(s)

Enterprise Edition 5.0 < 5.26.22

Enterprise Edition 2025.01 < 2026.02

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.