๐Ÿ” CVE Alert

CVE-2026-1497

UNKNOWN 0.0

Incorrect privilege assignment in composite databases

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:ย  an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently grant access to any local database or remote alias called "name". If such database or alias doesn't exist when the command is run, the privileges will apply if it's created in the future.

CWE CWE-863
Vendor neo4j
Product enterprise edition
Published Mar 11, 2026
Last Updated Mar 12, 2026
Stay Ahead of the Next One

Get instant alerts for neo4j enterprise edition

Be the first to know when new unknown vulnerabilities affecting neo4j enterprise edition are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

neo4j / Enterprise Edition
5.0 < 5.26.22 2025.01 < 2026.02

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
neo4j.com: https://neo4j.com/security/CVE-2026-1497