Threat Advisory

Neo4j GraphQL Flaw Lets Attackers Forge JWT Claims Over WebSocket Subscriptions

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity authentication bypass flaw, tracked as CVE-2026-5423 with a CVSS score of 8.2, affects the Neo4j GraphQL Library before versions 7.5.6 and 5.12.14, allowing an unauthenticated attacker to forge JWT claims over WebSocket subscriptions and access sensitive real-time data meant for authenticated users through Subscription Authentication Bypass via Unverified connectionParams.jwt; this flaw turns a trusted feature into an open door by failing to verify the authenticity of client-supplied, pre-decoded JWT objects, exposing confidential subscription events on the network; the affected version range is 7.0.0 up to 7.5.6 and 5.0.0 up to 5.12.14, as well as the entire v6 line which is end-of-life; this authentication bypass has a high confidentiality impact but does not allow writes or denial of service attacks.

RECOMMENDATION:

We recommend you to update Neo4j GraphQL Library to version 7.5.6 or 5.12.14.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity authentication bypass flaw, tracked as CVE-2026-5423 with a CVSS score of 8.2, affects the Neo4j GraphQL Library before versions 7.5.6 and 5.12.14, allowing an unauthenticated attacker to forge JWT claims over WebSocket subscriptions and access sensitive real-time data meant for authenticated users through Subscription Authentication Bypass via Unverified connectionParams.jwt; this flaw turns a trusted feature into an open door by failing to verify the authenticity of client-supplied, pre-decoded JWT objects, exposing confidential subscription events on the network; the affected version range is 7.0.0 up to 7.5.6 and 5.0.0 up to 5.12.14, as well as the entire v6 line which is end-of-life; this authentication bypass has a high confidentiality impact but does not allow writes or denial of service attacks.

RECOMMENDATION:

We recommend you to update Neo4j GraphQL Library to version 7.5.6 or 5.12.14.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu