CVE-2026-5423
Received
Received - Intake
Authentication Bypass in Neo4j GraphQL Library
Vulnerability report for CVE-2026-5423, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-06
Last updated on: 2026-08-06
Assigner: Neo4j
Description
Description
@neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL subscription connectionParams. As a result, any unauthenticated remote client that can open a GraphQL-over-WebSocket connection can forge arbitrary JWT claims (e.g. sub, roles) in connectionParams.jwt and have them accepted as authenticated identity for the purposes of @authentication and @subscriptionsAuthorization directive evaluation. This allows a fully unauthenticated attacker to receive subscription events that should be restricted to specific authenticated roles/users.
Upgrade the library to versions 7.5.6+ or 5.12.14+. v6 is end-of-life and will not receive a fix.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| neo4j | graphql | From 5.12.14 (inc) to 7.5.6 (exc) |
| neo4j | graphql | From 5.12.14 (inc) to 5.12.14 (exc) |
| neo4j | graphql | to 5.12.14 (exc) |
| neo4j | graphql | to 7.5.6 (exc) |
| neo4j | graphql | From 7.5.6 (inc) |
| neo4j | graphql | From 5.12.14 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-302 | The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker. |