Subscription Authentication Bypass via Unverified connectionParams.jwt
Summary
| CVE | CVE-2026-5423 |
|---|---|
| State | PUBLISHED |
| Assigner | Neo4j |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-06 16:16:44 UTC |
| Updated | 2026-08-18 15:04:46 UTC |
| Description | @neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL subscription connectionParams. As a result, any unauthenticated remote client that can open a GraphQL-over-WebSocket connection can forge arbitrary JWT claims (e.g. sub, roles) in connectionParams.jwt and have them accepted as authenticated identity for the purposes of @authentication and @subscriptionsAuthorization directive evaluation. This allows a fully unauthenticated attacker to receive subscription events that should be restricted to specific authenticated roles/users. Upgrade the library to versions 7.5.6+ or 5.12.14+. v6 is end-of-life and will not receive a fix. |
Risk And Classification
Primary CVSS: v4.0 8.2 HIGH from 3b236295-4ccd-4a1f-a1c1-a72eecc8d7b6
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.003350000 probability, percentile 0.263960000 (date 2026-08-18)
Problem Types: CWE-302 | CWE-302 CWE-302 Authentication bypass by Assumed-Immutable data
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 3b236295-4ccd-4a1f-a1c1-a72eecc8d7b6 | Secondary | 8.2 | HIGH | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 8.2 | HIGH | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/neo4j/graphql/security/advisories/GHSA-fcpg-3fw5-vc65 | 3b236295-4ccd-4a1f-a1c1-a72eecc8d7b6 | github.com | |
| neo4j.com/security/CVE-2026-5423 | 3b236295-4ccd-4a1f-a1c1-a72eecc8d7b6 | neo4j.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: EQSTLab (https://github.com/EQSTLab) (en)
Additional Advisory Data
Solutions
CNA: Fixed in 5.12.14 (LTS) and 7.5.6 (current). The 6.x line is end-of-life and will not receive a patch; users on 6.x must upgrade to 5.12.14+ or 7.5.6+.