Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-1622— Unredacted data exposure in query.log

Quick assessment

Affected
neo4j Enterprise Edition
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Neo4j Enterprise Edition和Neo4j Community Edition都是美国Neo4j公司的一款图数据库。 Neo4j Enterprise和Neo4j Community 2026.01.3之前版本和5.26.21之前版本存在安全漏洞,该漏洞源于查询日志中的错误信息未编辑,可能导致信息泄露。

AI Predicted 5.5 Difficulty: Easy EPSS 0.14% · P4

Possible ATT&CK Techniques 1 AI

T1005 · Data from Local System
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-1622

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unredacted data exposure in query.log
Source: CVE Program / CVE List V5
Vulnerability Description
Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 are vulnerable to a potential information disclosure by a user who has ability to access the local log files. The "obfuscate_literals" option in the query logs does not redact error information, exposing unredacted data in the query log when a customer writes a query that fails. It can allow a user with legitimate access to the local log files to obtain information they are not authorised to see. If this user is also in a position to run queries and trigger errors, this vulnerability can potentially help them to infer information they are not authorised to see through their intended database access. We recommend upgrading to versions 2026.01.3 (or 5.26.21) where the issue is fixed, and reviewing query log files permissions to ensure restricted access. If your configuration had db.logs.query.obfuscate_literals enabled, and you wish the obfuscation to cover the error messages as well, you need to enable the new configuration setting db.logs.query.obfuscate_errors once you have upgraded Neo4j.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:D/RE:M
Source: CVE Program / CVE List V5
Vulnerability Type
通过日志文件的信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
Neo4j Enterprise Edition和Neo4j Community Edition 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Neo4j Enterprise Edition和Neo4j Community Edition都是美国Neo4j公司的一款图数据库。 Neo4j Enterprise和Neo4j Community 2026.01.3之前版本和5.26.21之前版本存在安全漏洞,该漏洞源于查询日志中的错误信息未编辑,可能导致信息泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
neo4j Enterprise Edition 2025.01 ~ 2026.01.3 -
neo4j Community Edition 2025.01 ~ 2026.01.3 -

II. Public POCs for CVE-2026-1622

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-1622

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2026-1622

No comments yet


Leave a comment