JWT Authentication Bypass in Neo4j GraphQL Library
CVE-2026-5423

8.2HIGH

Key Information:

Vendor

Neo4j

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-5423?

The Neo4j GraphQL library versions prior to 7.5.6 and 5.12.14 are susceptible to a vulnerability where the authenticity of client-supplied JWT tokens is not properly verified during GraphQL subscription connections. This flaw allows unauthenticated remote clients to forge JWT claims, thereby gaining unauthorized access to restricted subscription events. Attackers can exploit this vulnerability to manipulate user roles and identities, undermining the application's authentication mechanisms. It's crucial to upgrade to the latest versions to mitigate this risk.

Affected Version(s)

graphql 7.0.0 < 7.5.6

graphql 5.0.0 < 5.12.14

graphql 6.0.0 <= 6.6.4

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

EQSTLab (https://github.com/EQSTLab)
.