Most of the 15 CVEs are Denial of Service vulnerabilities affecting Elasticsearch (ES|QL, EQL, search-query parsing) and Kibana (Machine Learning, Canvas, Entity Analytics), within the Elastic Stack. The remaining CVEs relate to authorization and access-control weaknesses in Kibana, including Missing/Incorrect Authorization and an SSRF via an incomplete input denylist, that can lead to unauthorized information disclosure or integrity compromise.
Fix Soft States Some checks that were actually failing showed up as green/OK in Icinga. The cause: two parts of the system stored the same status in different formats, so the web interface misread it and hid early-stage problems. A Read More
Fix Director self-service api We fixed the uncaught exception on bad Basic autm but in doing so we introduced a 302 redirect for API requests as well. Net result: a curl client expecting a 401 gets redirected to the login Read More
Why Dashboards Are Important In the modern IT world, simply collecting data isn't enough: Real value comes when data can be quickly interpreted and transformed into useful information. Dashboards represent the final step of a process that starts with: Data Read More
Important: Icinga 2 security update Type/Severity NetEye Product Security has rated this update as having a critical security impact. Topic An update for the icinga package is now available for NetEye 4. Security Fix for NetEye 4.48 2.15.5_neteye1.71.2-1 Summary The vulnerabilities include an Read More
Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a Medium security impact. Topic An update for the Kibana package is now available for NetEye 4. Security Fix for NetEye 4.48 9.4.3_neteye3.101.2-1 CVEs CVE-2026-56148CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2026-56149CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2026-56151CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H All Read More