Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:
an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently grant access to any local database or remote alias called "name". If such database or alias doesn't exist when the command is run, the privileges will apply if it's created in the future.
an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently grant access to any local database or remote alias called "name". If such database or alias doesn't exist when the command is run, the privileges will apply if it's created in the future.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://neo4j.com/security/CVE-2026-1497 |
|
History
Wed, 11 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario: an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently grant access to any local database or remote alias called "name". If such database or alias doesn't exist when the command is run, the privileges will apply if it's created in the future. | |
| Title | Incorrect privilege assignment in composite databases | |
| First Time appeared |
Neo4j
Neo4j enterprise Edition |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:neo4j:enterprise_edition:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Neo4j
Neo4j enterprise Edition |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Neo4j
Published:
Updated: 2026-03-11T15:50:57.651Z
Reserved: 2026-01-27T15:57:15.975Z
Link: CVE-2026-1497
No data.
Status : Received
Published: 2026-03-11T16:16:22.650
Modified: 2026-03-11T16:16:22.650
Link: CVE-2026-1497
No data.
OpenCVE Enrichment
No data.
Weaknesses