Information Disclosure Vulnerability in Neo4j Enterprise and Community Editions
CVE-2026-1622
Key Information:
- Vendor
Neo4j
- Vendor
- CVE Published:
- 4 February 2026
What is CVE-2026-1622?
Neo4j Enterprise and Community editions before versions 2026.01.3 and 5.26.21 exhibit a vulnerability that permits information disclosure through unredacted error messages in query logs. When customers execute failing queries, sensitive data can be unintentionally revealed to users who have access to local log files. This risk becomes acute for users capable of executing queries, as they might infer confidential information from error messages due to the ineffective obfuscation of literals. It is crucial for affected users to upgrade their installations and review log file permissions to restrict unauthorized data access. Additionally, enabling the new configuration setting 'db.logs.query.obfuscate_errors' after upgrading can further enhance data protection.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Community Edition 2025.01 < 2026.01.3
Community Edition 5.0 < 5.26.21
Community Edition 4.4 < 4.4.48
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
