
CVE-2026-19869 @neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-level @authenticati… https://www.cve.org/CVERecord?id=CVE-2026-19869
Post summary
CVE-2026-19869 in @neo4j/graphql allows unauthorized access due to a missing enforcement of field-level authentication rules; patched versions address the issue.

