SSO Implementation Flaw in Neo4j Enterprise Edition
CVE-2026-1524
2.1LOW
What is CVE-2026-1524?
An edge case in the Single Sign-On (SSO) implementation for Neo4j Enterprise Edition can lead to security concerns. This occurs when an administrator configures multiple OpenID Connect (OIDC) providers, with some designated for authentication-only while others serve both authentication and authorization roles. If the authentication-only provider contains groups with higher privileges than intended, it could inadvertently provide authorization capabilities, increasing the risk of unauthorized access. To mitigate this risk, upgrade to version 2026.02 or higher, where this issue has been addressed.
Affected Version(s)
Enterprise Edition 4.4.0 < 5.26.22
Enterprise Edition 2025.01 < 2026.02
