CVE-2026-1524
Severity CVSS v4.0:
LOW
Type:
CWE-287
Authentication Issues
Publication date:
11/03/2026
Last modified:
11/03/2026
Description
An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions:<br />
<br />
<br />
If a neo4j admin configures two or more OIDC providers AND configures one or more of them to be an authorization provider AND configures one or more of them to be authentication-only, then those that are authentication-only will also provide authorization. This edgecase becomes a security problem only if the authentication-only provider contains groups which have higher privileges than provided by the intended (configured) authorization provider. <br />
<br />
When using multiple plugins for authentication and authorisation, prior to the fix the issue could lead to a plugin configured to provide only authentication or authorisation capabilities erroneously providing both capabilities. <br />
<br />
We recommend upgrading to versions 2026.02 (or 5.26.22) where the issue is fixed.



