CVE-2026-1497 describes an incorrect namespace resolution vulnerability affecting Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22. This flaw allows an administrator attempting to grant user access to a specific remote database to inadvertently grant access to any local database or remote alias with a matching simple name, potentially leading to unintended data exposure or modification. Rated with a CVSS 4.0 score of 2.0 (LOW), the vulnerability requires administrator action and authenticated user privileges to trigger, with low impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability, and it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.26.22CPE matchmatch criteria | cpe:2.3:a:neo4j:neo4j:*:*:*:*:enterprise:*:*:* | ||
>= 2025.01.0, < 2026.02CPE matchmatch criteria | cpe:2.3:a:neo4j:neo4j:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Green
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.