SCA: security update for org.neo4j:neo4j (GHSA-4j3g-rwwq-4p54)

medium Tenable Self-Hosted Container Security Plugin ID 437545

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 are vulnerable to a
potential information disclosure by a user who has ability to access the local log files. The
"obfuscate_literals" option in the query logs does not redact error information, exposing unredacted data
in the query log when a customer writes a query that fails. It can allow a user with legitimate access to
the local log files to obtain information they are not authorised to see. If this user is also in a
position to run queries and trigger errors, this vulnerability can potentially help them to infer
information they are not authorised to see through their intended database access. We recommend upgrading
to versions 2026.01.3 (or 5.26.21) where the issue is fixed, and reviewing query log files permissions to
ensure restricted access. If your configuration had db.logs.query.obfuscate_literals enabled, and you wish
the obfuscation to cover the error messages as well, you need to enable the new configuration setting
db.logs.query.obfuscate_errors once you have upgraded Neo4j. (CVE-2026-1622)

See Also

https://github.com/advisories/GHSA-4j3g-rwwq-4p54

Plugin Details

Severity: Medium

ID: 437545

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 2/5/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.73

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2026-1622

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 4.8

Threat Score: 1.1

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/4/2026

Vulnerability Publication Date: 2/4/2026

Reference Information

CVE: CVE-2026-1622

cwe: CWE-532