{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-5423","assignerOrgId":"3b236295-4ccd-4a1f-a1c1-a72eecc8d7b6","state":"PUBLISHED","assignerShortName":"Neo4j","dateReserved":"2026-04-02T13:17:29.975Z","datePublished":"2026-08-06T15:15:29.124Z","dateUpdated":"2026-08-06T15:45:22.183Z"},"containers":{"cna":{"providerMetadata":{"orgId":"3b236295-4ccd-4a1f-a1c1-a72eecc8d7b6","shortName":"Neo4j","dateUpdated":"2026-08-06T15:15:29.124Z"},"title":"Subscription Authentication Bypass via Unverified connectionParams.jwt","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-302","description":"CWE-302 Authentication bypass by Assumed-Immutable data","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-115","descriptions":[{"lang":"en","value":"CAPEC-115 Authentication Bypass"}]}],"affected":[{"vendor":"neo4j","product":"graphql","collectionURL":"https://registry.npmjs.org","packageName":"@neo4j/graphql","repo":"https://github.com/neo4j/graphql","versions":[{"status":"affected","version":"7.0.0","lessThan":"7.5.6","versionType":"semver"},{"status":"affected","version":"5.0.0","lessThan":"5.12.14","versionType":"semver"},{"status":"affected","version":"6.0.0","lessThanOrEqual":"6.6.4","versionType":"semver"}],"defaultStatus":"unaffected"}],"cpeApplicability":[{"operator":"OR","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:neo4j:graphql:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0.0","versionEndExcluding":"7.5.6"},{"vulnerable":true,"criteria":"cpe:2.3:a:neo4j:graphql:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.0","versionEndExcluding":"5.12.14"},{"vulnerable":true,"criteria":"cpe:2.3:a:neo4j:graphql:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0.0","versionEndIncluding":"6.6.4"}]}]}],"descriptions":[{"lang":"en","value":"@neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL subscription connectionParams. As a result, any unauthenticated remote client that can open a GraphQL-over-WebSocket connection can forge arbitrary JWT claims (e.g. sub, roles) in connectionParams.jwt and have them accepted as authenticated identity for the purposes of @authentication and @subscriptionsAuthorization directive evaluation. This allows a fully unauthenticated attacker to receive subscription events that should be restricted to specific authenticated roles/users.\nUpgrade the library to versions 7.5.6+ or 5.12.14+. v6 is end-of-life and will not receive a fix.","supportingMedia":[{"type":"text/html","base64":false,"value":"<code>@neo4j/graphql</code>&nbsp;library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL subscription&nbsp;<code>connectionParams.&nbsp;</code>As a result, any unauthenticated remote client that can open a GraphQL-over-WebSocket connection can forge arbitrary JWT claims (e.g.&nbsp;<code>sub</code>,&nbsp;<code>roles</code>) in&nbsp;<code>connectionParams.jwt</code>&nbsp;and have them accepted as authenticated identity for the purposes of&nbsp;<code>@authentication</code>&nbsp;and&nbsp;<code>@subscriptionsAuthorization</code>&nbsp;directive evaluation. This allows a fully unauthenticated attacker to receive subscription events that should be restricted to specific authenticated roles/users.<br>Upgrade the library to versions 7.5.6+ or 5.12.14+. v6 is end-of-life and will not receive a fix."}]}],"references":[{"url":"https://neo4j.com/security/CVE-2026-5423","tags":["vendor-advisory"]},{"url":"https://github.com/neo4j/graphql/security/advisories/GHSA-fcpg-3fw5-vc65","tags":["third-party-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"HIGH","baseScore":8.2,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}}],"configurations":[{"lang":"en","value":"The application enables `features.subscriptions` and `features.authorization`, and wires the subscriptions transport (e.g. `graphql-ws`) to forward WebSocket `connectionParams` into the resolver context.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>The application enables `features.subscriptions` and `features.authorization`, and wires the subscriptions transport (e.g. `graphql-ws`) to forward WebSocket `connectionParams` into the resolver context.</p>"}]}],"credits":[{"lang":"en","value":"EQSTLab (https://github.com/EQSTLab)","type":"reporter"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 1.0.2"},"solutions":[{"lang":"en","value":"Fixed in 5.12.14 (LTS) and 7.5.6 (current). The 6.x line is end-of-life and will not receive a patch; users on 6.x must upgrade to 5.12.14+ or 7.5.6+.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>Fixed in 5.12.14 (LTS) and 7.5.6 (current). The 6.x line is end-of-life and will not receive a patch; users on 6.x must upgrade to 5.12.14+ or 7.5.6+.</p>"}]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-06T15:45:16.532890Z","id":"CVE-2026-5423","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-06T15:45:22.183Z"}}]}}