Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-1471

Опубликовано: 11 мар. 2026
Источник: redhat
CVSS3: 4.2
EPSS Низкий

Описание

A flaw was found in Neo4j. Authenticated users can inherit the authentication context of the first user who authenticated after a system restart. This occurs due to excessive caching of authentication context in certain non-default configurations of the Single Sign-On (SSO) UserInfo endpoint. This could lead to unauthorized access to resources or actions intended for the initial user.

Отчет

This LOW impact vulnerability affects Neo4j Enterprise edition versions prior to 2026.01.4. Authenticated users may inherit another user's authentication context due to excessive caching in SSO. Exploitation requires high complexity—non-default SSO configuration and timing relative to restart. Impact is limited since the attacker cannot control whose context they inherit. Red Hat products are affected if using vulnerable Neo4j versions with SSO UserInfo endpoint enabled.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4camel-neo4jFix deferred
Red Hat build of Apache Camel for Spring Boot 4neo4j-bolt-connectionFix deferred
Red Hat build of Apache Camel for Spring Boot 4neo4j-bolt-connection-nettyFix deferred
Red Hat build of Apache Camel for Spring Boot 4neo4j-bolt-connection-pooledFix deferred
Red Hat build of Apache Camel for Spring Boot 4neo4j-bolt-connection-routedFix deferred
Red Hat build of Apache Camel for Spring Boot 4neo4j-java-driverFix deferred
Red Hat Fuse 7neo4j-ogm-coreFix deferred
Red Hat JBoss Enterprise Application Platform 8neo4jFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packneo4jFix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-model-registry-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-488
https://bugzilla.redhat.com/show_bug.cgi?id=2446566neo4j: Neo4j: Authentication context inheritance via excessive caching in SSO UserInfo endpoint

EPSS

Процентиль: 16%
0.0005
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

nvd
19 дней назад

Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the context of the first user who authenticated after restart. The issue is limited to certain non-default configurations of SSO (UserInfo endpoint).  We recommend upgrading to versions 2026.01.4 (or 5.26.22) where the issue is fixed.

github
19 дней назад

Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the context of the first user who authenticated after restart. The issue is limited to certain non-default configurations of SSO (UserInfo endpoint).  We recommend upgrading to versions 2026.01.4 (or 5.26.22) where the issue is fixed.

EPSS

Процентиль: 16%
0.0005
Низкий

4.2 Medium

CVSS3