Caching of authentication context
Summary
| CVE | CVE-2026-1471 |
|---|---|
| State | PUBLISHED |
| Assigner | Neo4j |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-03-11 17:16:54 UTC |
| Updated | 2026-03-12 21:08:22 UTC |
| Description | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the context of the first user who authenticated after restart. The issue is limited to certain non-default configurations of SSO (UserInfo endpoint). We recommend upgrading to versions 2026.01.4 (or 5.26.22) where the issue is fixed. |
Risk And Classification
Primary CVSS: v4.0 2.1 LOW from 3b236295-4ccd-4a1f-a1c1-a72eecc8d7b6
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Clear
EPSS: 0.000710000 probability, percentile 0.218900000 (date 2026-05-28)
Problem Types: CWE-863 | CWE-863 CWE-863 Incorrect Authorization
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 3b236295-4ccd-4a1f-a1c1-a72eecc8d7b6 | Secondary | 2.1 | LOW | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 2.1 | LOW | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/AU:N/... |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
PresentPrivileges Required
LowUser Interaction
PassiveConfidentiality
LowIntegrity
LowAvailability
LowSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Clear
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Neo4j | Enterprise Edition | affected 2025.01 2026.01.4 date | Not specified |
| CNA | Neo4j | Enterprise Edition | affected 4.4.0 5.26.22 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| neo4j.com/security/CVE-2026-1471 | 3b236295-4ccd-4a1f-a1c1-a72eecc8d7b6 | neo4j.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Workarounds
CNA: Set dbms.security.oidc.<provider>.get_groups_from_user_info and dbms.security.oidc.<provider>.get_username_from_user_info to false.
There are currently no legacy QID mappings associated with this CVE.