A high-severity flaw tracked as CVE-2026-5423 was disclosed in the @neo4j/graphql library, allowing unauthenticated remote attackers to bypass subscription authentication over GraphQL WebSocket connections. The issue stems from the library accepting a pre-decoded JWT object supplied in connectionParams.jwt without verification, causing forged claims to be treated as an authenticated identity during subscription setup.
Successful exploitation can let attackers evade controls enforced by @authentication and @subscriptionsAuthorization directives and receive subscription events intended only for specific users or roles, creating risks of information disclosure, spoofing, and security restriction bypass. Affected releases include 7.0.0 through before 7.5.6, 5.0.0 through before 5.12.14, and all 6.x versions through 6.6.4; Neo4j has advised customers to upgrade to 7.5.6+ or 5.12.14+, while the 6.x branch is end-of-life and will not receive a fix.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A new CVE, CVE-2026-5423, was recorded for the @neo4j/graphql library. The flaw allows unauthenticated remote clients using GraphQL-over-WebSocket subscriptions to supply a pre-decoded JWT object in connectionParams and have forged claims accepted as authenticated identity.
Neo4j advised users to upgrade @neo4j/graphql to version 7.5.6 or later or 5.12.14 or later to remediate the vulnerability. The vendor also stated that the 6.x branch is end-of-life and will not receive a fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.