CVE-2026-1622 is an information disclosure vulnerability affecting Neo4j Enterprise and Community editions prior to versions 2026.01.3 and 5.26.21. The "obfuscate_literals" option in query logs fails to redact error information, exposing unredacted data when a query fails. This allows a user with legitimate local log file access to potentially infer unauthorized information, especially if they can trigger errors. The vulnerability has a CVSS v4.0 score of 4.8 (Medium), indicating a low attack complexity and requiring local access (AV:L/AC:L/PR:L). The primary impact is a low potential for confidentiality compromise (VC:L), as it can lead to unauthorized information disclosure. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Neo4j | Community Edition | >= 2025.01, < 2026.01.3, >= 4.4, < 4.4.48, >= 5.0, < 5.26.21CNA affecteddefault unaffected | |
| Neo4j | Enterprise Edition | >= 2025.01, < 2026.01.3, >= 4.4, < 4.4.48, >= 5.0, < 5.26.21CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.