Most of the 11 CVEs are authorization and access control weaknesses affecting Kibana, including Missing/Incorrect Authorization (Fleet metadata disclosure, ML resource abuse, Entity Store API key creation, APM credential disclosure, AI Assistant Knowledge Base tampering, unauthorized ML data reads, disabled Entity Analytics monitoring) and resource-exhaustion issues in Agent Builder and Streams content packs, within the Elastic Stack. The remaining CVE is an Incorrect Permission Assignment for Critical Resource in Elastic Agent, affecting unprivileged Windows installations, that can lead to local privilege escalation to SYSTEM. Together, these CVEs can lead to unauthorized information disclosure, privilege escalation, data tampering, or denial of service.
Historical log data is valuable—until the cost of keeping every shard online starts competing with the value of the data itself. Elasticsearch searchable snapshots offer a practical middle ground for a NetEye installation: keep an index in a snapshot repository, Read More
Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a critical security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.49 26.7.2_neteye1.46.1-1 Summary This vulnerability, tracked as CVE-2026-18963 Read More
Important: Icinga 2 security update Type/Severity NetEye Product Security has rated this update as having a medium security impact. Topic An update for the icinga package is now available for NetEye 4. Security Fix for NetEye 4.49 2.15.6_neteye1.73.1-1 Summary This release fixes authorization Read More
RKE2 Otel Collector DNS requirement During updates and first installations on systems where the Elastic Stack feature module was installed, an extra requirement was present. In particular, the DNS defined in the resolv.conf of the machine was required to resolve Read More
Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a High security impact. Topic Updates for the Elastic Stack packages are now available for NetEye 4. Security Fix for NetEye 4.49 9.4.5_neteye3.103.7-1 CVEs Elasticsearch Read More