securityonline.info 8/10/2026, 3:11:11 PM · external

Neo4j GraphQL Library flaw lets attackers bypass auth via WebSocket

Neo4j GraphQL Library flaw lets attackers bypass auth via WebSocket
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A high-severity authentication bypass vulnerability affecting the Neo4j GraphQL Library has been identified, tracked as CVE-2026-5423, with a CVSS score of 8.2. The flaw exists in versions 7.0.0 to 7.5.6 and 5.0.0 to 5.12.14, allowing unauthorized attackers to forge JWT claims via WebSocket subscriptions, exposing real-time data meant for authenticated users. The issue arises from the library's failure to verify the authenticity of JWT objects in the connection parameters.

No confirmed exploits are reported, but it's critical to upgrade to patched versions 7.5.6 and 5.12.14. If immediate patching isn't possible, restricting access to the WebSocket endpoint is advised.

View Primary Source Via securityonline.info

Article by CyberSIXT