17. 09. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4 – Security Advisory (Grafana)

Important: Grafana security update

Type/Severity

NetEye Product Security has rated this update as having a high security impact.

Topic

An update for the grafana packages is now available for NetEye 4.

Security Fix for NetEye 4.49

  • grafana-12.4.11_neteye3.31.3-1

Summary

An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana’s configured datasource credentials to users who lack permission to query that datasource.

For details on how to apply this update, which includes the changes described in this advisory, refer to the NetEye Update Section in the User Guide.

Affected Products

All NetEye 4.x versions

References

Patrick Harasser

Patrick Harasser

Author

Patrick Harasser

Leave a Reply

Your email address will not be published. Required fields are marked *

Archive