A high-severity authentication bypass vulnerability affecting the Neo4j GraphQL Library has been identified, tracked as CVE-2026-5423, with a CVSS score of 8.2. The flaw exists in versions 7.0.0 to 7.5.6 and 5.0.0 to 5.12.14, allowing unauthorized attackers to forge JWT claims via WebSocket subscriptions, exposing real-time data meant for authenticated users. The issue arises from the library's failure to verify the authenticity of JWT objects in the connection parameters.
No confirmed exploits are reported, but it's critical to upgrade to patched versions 7.5.6 and 5.12.14. If immediate patching isn't possible, restricting access to the WebSocket endpoint is advised.