mcp-neo4j-cypher read-only bypass via APOC procedures (CVE-2026-35402)
In mcp-neo4j-cypher versions before 0.6.0, an MCP server for running Cypher queries against Neo4j, the read_only mode enforcement could be bypassed using APOC CALL procedures, potentially enabling unauthorized write operations or server-side request forgery. The issue is fixed in version 0.6.0.
Disclosed 17 April 2026 · Record updated 13 September 2026
Impact
Allows bypass of read-only restrictions, potentially permitting unauthorized database writes or server-side request forgery from the MCP server.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-35402
