
A PoC/exploit has been discovered for vulnerability CVE-2026-46591 PT ID: PT-2026-55896 Vendor: Apache Software Foundation Product: Apache Camel Description: An issue exists in the Apache Camel Neo4J component where the producer builds the Cypher WHERE clause for match, retrieve, and delete operations using the CamelNeo4jMatchProperties map. While property values are bound as parameters, the property names (JSON keys of the map) are concatenated directly into the query string within the retrieveNodes() and deleteNode() functions. This allows an attacker who can control the JSON key names to inject arbitrary Cypher syntax, potentially enabling them to read, modify, or delete any node or relationship in the Neo4J database. This is possible in routes that map untrusted input into the CamelNeo4jMatchProperties map or use consumers that do not filter inbound Camel headers. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-55896 • https://github.com/oscerd/CVE-2026-46591 #dbugs_vuln
Post summary
PoC and exploit code for CVE-2026-46591 are publicly available with technical details, but no evidence of active exploitation or a patch.

