THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-1497 (HIGH 7.2) — Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:  an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently gran

[NVD] CVE-2026-1497 (HIGH 7.2) — Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:  an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently gran

lownvdPublished 2026-03-11

CVE-2026-1497 CVSS: 7.2 HIGH Published: 2026-03-11T16:16:22.650

Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:  an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently grant access to any local database or remote alias called "

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-1497