Information Disclosure Vulnerability in Neo4j Enterprise and Community Editions
CVE-2026-1622

4.8MEDIUM

Key Information:

Vendor

Neo4j

Vendor
CVE Published:
4 February 2026

What is CVE-2026-1622?

Neo4j Enterprise and Community editions before versions 2026.01.3 and 5.26.21 exhibit a vulnerability that permits information disclosure through unredacted error messages in query logs. When customers execute failing queries, sensitive data can be unintentionally revealed to users who have access to local log files. This risk becomes acute for users capable of executing queries, as they might infer confidential information from error messages due to the ineffective obfuscation of literals. It is crucial for affected users to upgrade their installations and review log file permissions to restrict unauthorized data access. Additionally, enabling the new configuration setting 'db.logs.query.obfuscate_errors' after upgrading can further enhance data protection.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Community Edition 2025.01 < 2026.01.3

Community Edition 5.0 < 5.26.21

Community Edition 4.4 < 4.4.48

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.