CVE-2026-5423 | Neo4j graphql up to 5.12.13/6.6.4/7.5.5 Authentication jwt improper authorization

SecurityVulns

A vulnerability categorized as critical has been discovered in Neo4j graphql up to 5.12.13/6.6.4/7.5.5. The impacted element is an unknown function of the component Authentication. The manipulation of the argument jwt results in improper authorization.

This vulnerability is identified as CVE-2026-5423. The attack can be executed remotely. There is not any exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More