CVE-2026-35402
Received Received - Intake
Bypass of Read-Only Enforcement via APOC in mcp-neo4j-cypher

Publication date: 2026-04-17

Last updated on: 2026-04-17

Assigner: GitHub, Inc.

Description
mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the read_only mode enforcement can be bypassed using APOC CALL procedures, potentially allowing unauthorized write operations or server-side request forgery. This issue is fixed in version 0.6.0.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-17
Last Modified
2026-04-17
Generated
2026-06-16
AI Q&A
2026-04-18
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
neo4j mcpc-neo4j-cypher to 0.6.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The vulnerability exists in mcp-neo4j-cypher, an MCP server used to execute Cypher queries on Neo4j databases. In versions before 0.6.0, the enforcement of read_only mode can be bypassed by using APOC CALL procedures. This bypass allows unauthorized write operations or server-side request forgery, meaning attackers could perform actions that should be restricted.

Impact Analysis

This vulnerability can impact you by allowing unauthorized write operations on your Neo4j database through the MCP server. It could also enable server-side request forgery, potentially leading to further exploitation or unauthorized access to internal resources. Essentially, it compromises the integrity and security of your database operations.

Mitigation Strategies

To mitigate this vulnerability, upgrade mcp-neo4j-cypher to version 0.6.0 or later, where the read_only mode enforcement bypass issue is fixed.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-35402. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart