NetEye Product Security has rated this update as having a high security impact.
Topic
An update for the keycloak packages is now available for NetEye 4.
Security Fix for NetEye 4.49
26.7.3_neteye1.46.1-1
Summary
This Keycloak update (version 26.7.3) fixes 20 security issues found during internal review. None of them are rated Critical for running systems. The two most serious,CVE-2026-18215 and CVE-2026-18214 (CVSS 8.1), could let an external login provider (Microsoft or Google) bypass the organization/tenant restriction configured for it, potentially letting an account from outside the allowed company or domain log in. Another issue, CVE-2026-18571(CVSS 7.2), could let a delegated administrator assign a user to groups they aren’t supposed to manage. The remaining issues are lower-severity gaps in permission checks and edge cases in login/authorization handling, with limited practical impact on their own. There is no evidence of active exploitation of any of these issues.
For details on how to apply this update, refer to the NetEye Update Section in the User Guide.
Icinga 2 live-creation requests are no longer lost during reload During a Director deployment, Icinga 2 reloads its configuration in the background. Previously, live-creation requests could still be processed for a short time after a reload had been requested. This Read More
Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a High security impact. Topic Updates for the Elastic Stack packages are now available for NetEye 4. Security Fix for NetEye 4.49 9.4.6_neteye3.103.8-1 CVEs Elastic Read More
Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a critical security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.49 26.7.2_neteye1.46.1-1 Summary This vulnerability, tracked as CVE-2026-18963 Read More
Important: Icinga 2 security update Type/Severity NetEye Product Security has rated this update as having a medium security impact. Topic An update for the icinga package is now available for NetEye 4. Security Fix for NetEye 4.49 2.15.6_neteye1.73.1-1 Summary This release fixes authorization Read More
RKE2 Otel Collector DNS requirement During updates and first installations on systems where the Elastic Stack feature module was installed, an extra requirement was present. In particular, the DNS defined in the resolv.conf of the machine was required to resolve Read More