SSO Implementation Flaw in Neo4j Enterprise Edition
CVE-2026-1524

2.1LOW

Key Information:

Vendor

Neo4j

Vendor
CVE Published:
11 March 2026

What is CVE-2026-1524?

An edge case in the Single Sign-On (SSO) implementation for Neo4j Enterprise Edition can lead to security concerns. This occurs when an administrator configures multiple OpenID Connect (OIDC) providers, with some designated for authentication-only while others serve both authentication and authorization roles. If the authentication-only provider contains groups with higher privileges than intended, it could inadvertently provide authorization capabilities, increasing the risk of unauthorized access. To mitigate this risk, upgrade to version 2026.02 or higher, where this issue has been addressed.

Affected Version(s)

Enterprise Edition 4.4.0 < 5.26.22

Enterprise Edition 2025.01 < 2026.02

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.