THREAT OPS › Threat News › [NVD] CVE-2026-1497 (HIGH 7.2) — Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:
an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently gran
[NVD] CVE-2026-1497 (HIGH 7.2) — Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario: an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently gran
CVE-2026-1497 CVSS: 7.2 HIGH Published: 2026-03-11T16:16:22.650
Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario: an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently grant access to any local database or remote alias called "
Indicators of compromise
- CVE-2026-1497cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-1497