03. 09. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4 – Security Advisory (Elastic Stack)

Important: Elastic Stack security update

Type/Severity

NetEye Product Security has rated this update as having a High security impact.

Topic

Updates for the Elastic Stack packages are now available for NetEye 4.

Security Fix for NetEye 4.49

  • 9.4.6_neteye3.103.8-1

CVEs

Elastic Agent

  1. CVE-2026-78604
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Kibana

  1. CVE-2026-78608
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  2. CVE-2026-72654
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  3. CVE-2026-72628
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  4. CVE-2026-72682
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  5. CVE-2026-72641
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
  6. CVE-2026-78603
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  7. CVE-2026-82293
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
  8. CVE-2026-78597
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  9. CVE-2026-72633
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
  10. CVE-2026-78606
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Most of the 11 CVEs are authorization and access control weaknesses affecting Kibana, including Missing/Incorrect Authorization (Fleet metadata disclosure, ML resource abuse, Entity Store API key creation, APM credential disclosure, AI Assistant Knowledge Base tampering, unauthorized ML data reads, disabled Entity Analytics monitoring) and resource-exhaustion issues in Agent Builder and Streams content packs, within the Elastic Stack. The remaining CVE is an Incorrect Permission Assignment for Critical Resource in Elastic Agent, affecting unprivileged Windows installations, that can lead to local privilege escalation to SYSTEM. Together, these CVEs can lead to unauthorized information disclosure, privilege escalation, data tampering, or denial of service.

Affected Products

All NetEye 4.x versions >= 4.25.

References

Patrick Harasser

Patrick Harasser

Author

Patrick Harasser

Leave a Reply

Your email address will not be published. Required fields are marked *

Archive