JWT Authentication Bypass in Neo4j GraphQL Library
CVE-2026-5423
8.2HIGH
What is CVE-2026-5423?
The Neo4j GraphQL library versions prior to 7.5.6 and 5.12.14 are susceptible to a vulnerability where the authenticity of client-supplied JWT tokens is not properly verified during GraphQL subscription connections. This flaw allows unauthenticated remote clients to forge JWT claims, thereby gaining unauthorized access to restricted subscription events. Attackers can exploit this vulnerability to manipulate user roles and identities, undermining the application's authentication mechanisms. It's crucial to upgrade to the latest versions to mitigate this risk.
Affected Version(s)
graphql 7.0.0 < 7.5.6
graphql 5.0.0 < 5.12.14
graphql 6.0.0 <= 6.6.4
