CVE-2026-1524

Severity CVSS v4.0:
LOW
Type:
CWE-287 Authentication Issues
Publication date:
11/03/2026
Last modified:
11/03/2026

Description

An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions:<br /> <br /> <br /> If a neo4j admin configures two or more OIDC providers AND configures one or more of them to be an authorization provider AND configures one or more of them to be authentication-only, then those that are authentication-only will also provide authorization. This edgecase becomes a security problem only if the authentication-only provider contains groups which have higher privileges than provided by the intended (configured) authorization provider. <br /> <br /> When using multiple plugins for authentication and authorisation, prior to the fix the issue could lead to a plugin configured to provide only authentication or authorisation capabilities erroneously providing both capabilities. <br /> <br /> We recommend upgrading to versions 2026.02 (or 5.26.22) where the issue is fixed.

References to Advisories, Solutions, and Tools