← Vulnerability feed

Vulnerability record · CVE-2026-14587 · published 5 August 2026

CVE-2026-14587: Neo4j vulnerability

Neo4j · Neo4j

Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the capability mask, the decoder resets the reader index and waits for more bytes instead of rejecting the protocol message and closing the channel. Because the same unread bytes remain at the front of the decoder buffer, appending a terminating byte later does not recover the connection. The decoder re-reads the same first 32 continuation bytes, returns without producing a handshake-finalization message, and leaves the channel open. This can be triggered before authentication by any client that can reach the Bolt connector.

5.5 CVSS 4.0 Medium EPSS 0.54% · top 56.7% CWE-130 · CWE-130
5.5CVSS 4.0 base score
0.54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
28 Aug 2026Last modified by NVD

Description

Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the capability mask, the decoder resets the reader index and waits for more bytes instead of rejecting the protocol message and closing the channel. Because the same unread bytes remain at the front of the decoder buffer, appending a terminating byte later does not recover the connection. The decoder re-reads the same first 32 continuation bytes, returns without producing a handshake-finalization message, and leaves the channel open. This can be triggered before authentication by any client that can reach the Bolt connector.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-14587 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-34371Neo4j deserialization of untrusted data vulnerabilityNeo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVaria…EPSS 13%9.8CVE-2018-18389Neo4j improper authentication vulnerabilityDue to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and Sys…EPSS 1.9%6.8CVE-2013-7259Neo4j os command injection vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of administrators for r…EPSS 1.3%6.5CVE-2024-34517Neo4j vulnerabilityThe Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.EPSS 0.63%2.1CVE-2026-1471Neo4j incorrect authorization vulnerabilityExcessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the conte…EPSS 0.24%2.1CVE-2026-1524Neo4j improper authentication vulnerabilityAn edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following c…EPSS 0.32%2.0CVE-2026-1497Neo4j incorrect authorization vulnerabilityIncorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following …EPSS 0.24%1.1CVE-2026-1337Neo4j vulnerabilityInsufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user open…EPSS 0.23%

Source: NIST National Vulnerability Database (record CVE-2026-14587), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.