CVE-2024-34517

Executive Summary

Neo4j 5.0.0‑5.18 Cypher component incorrectly handles IMMUTABLE privileges, allowing an attacker with admin rights to bypass privilege checks and potentially gain elevated access or modify data. The flaw exists only when admin privileges are already present, so it does not enable initial compromise but can be leveraged for privilege escalation or data tampering. No CISA KEV listing yet.


Authoritative CVE Metadata - CVSS Base Score: 6.5 (MEDIUM) - Published: 2024-05-07T18:15:08.467 - Last Modified: 2026-08-28T16:08:25.740

Original Description: The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

"No pessimist ever discovered the secrets of the stars, or sailed to an uncharted land, or opened a new heaven to the human spirit."

— Helen Keller
Source: NVD