CVE-2026-46591 is an improper neutralization vulnerability in the Apache Camel camel-neo4j producer. Match and delete operations construct Neo4j Cypher WHERE clauses using property names from the CamelNeo4jMatchProperties map. Although property values are parameterized, property names were concatenated into the Cypher query without validation or escaping. An attacker able to control those map keys can inject Cypher syntax and alter the query structure. Affected versions are Apache Camel 4.10.0 through 4.14.7, 4.15.0 through 4.18.2, and 4.19.0 through 4.20.x.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a runnable Java/Spring Boot proof-of-concept for CVE-2026-46591, a Cypher injection flaw in Apache Camel's camel-neo4j component. The core issue is that Camel parameterized match property values but still concatenated match property names directly into generated Cypher in Neo4jProducer.retrieveNodes() and deleteNode(). If untrusted input controls the keys of CamelNeo4jMatchProperties, an attacker can inject Cypher syntax and alter query structure. Repository structure: Application.java is the Spring Boot entry point. VictimRoute.java is the vulnerable path: it exposes platform-http:/lookup, converts the request body to a string, stores it in Neo4jHeaders.MATCH_PROPERTIES, sets operation RETRIEVE_NODES, and sends it to the Camel Neo4j endpoint targeting label Person. Neo4jConfig.java creates the Neo4j driver bean. Neo4jSettings.java centralizes host, port, credentials, database name, and the demo secret flag. Neo4jSeeder.java waits for Neo4j readiness and seeds two Person nodes plus one Secret node. ExploitController.java is the attacker harness: it calls the victim /lookup endpoint first with a benign JSON body and then with a malicious JSON key containing Cypher injection. Dockerfile and docker-compose.yml package the app with a Neo4j 5.26 container for easy reproduction. Main exploit capability: authorization bypass and data exfiltration from Neo4j by rewriting a Person lookup query into a UNION query that also returns Secret nodes. The hardcoded payload key is: name = $param0 RETURN n AS node UNION MATCH (s:Secret) RETURN s AS node //. This comments out the remainder of the generated template and causes the response to include the seeded secret FLAG. The README also notes the same primitive could be adapted for modification or deletion of arbitrary nodes/relationships via injected SET, DELETE, or DETACH DELETE clauses. Operational flow: a GET request to /exploit/attack triggers the exploit controller, which POSTs JSON to http://127.0.0.1:8080/lookup. The victim route forwards that body into Camel's Neo4j match-properties header, and the vulnerable Camel component builds Cypher against the Neo4j Bolt backend. This is a real exploit reproducer rather than a detector: it stands up the vulnerable service, seeds data, executes the attack, and verifies whether the secret leaked.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.