CVE-2026-1471 describes a low-severity vulnerability in Neo4j Enterprise edition versions prior to 2026.01.4, where excessive caching of authentication context can lead to authenticated users inheriting the privileges of the first user after a system restart under specific non-default SSO configurations. This issue has a CVSSv4 score of 2.1 (Low) with a network attack vector and low attack complexity, requiring low privileges and some user interaction, resulting in low impact to confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion or media coverage regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.26.22CPE matchmatch criteria | cpe:2.3:a:neo4j:neo4j:*:*:*:*:enterprise:*:*:* | ||
>= 2025.01.0, < 2026.01.4CPE matchmatch criteria | cpe:2.3:a:neo4j:neo4j:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Clear
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.