21. 09. 2026 Luca Tecchio Bug Fixes, NetEye

NetEye 4 – Security Advisory (Keycloak)

Important: Keycloak security update

Type/Severity

NetEye Product Security has rated this update as having a high security impact.

Topic

An update for the keycloak packages is now available for NetEye 4.

Security Fix for NetEye 4.49:

  • 26.7.4_neteye1.46.1-1

Summary

This Keycloak update (version 26.7.4) resolves several security issues identified in upstream Keycloak:

  • CVE-2026-90997: Default MySQL/MariaDB row counts make stateless replay gates accept reused artifacts
  • CVE-2026-79651: Keycloak Unauthenticated Denial of Service via Unbounded Locale Caching
  • CVE-2026-74909: Incomplete fix: percent-encoded semicolon bypasses matrix parameter stripping in PathMatcher
  • CVE-2026-19607: Username Takeover Leading to Account Lockout
  • CVE-2026-17526: Privilege escalation: the “impersonation” role can impersonate a realm administrator
  • CVE-2026-18212: SAML Redirect DEFLATE helpers leak native zlib state

For details on how to apply this update, which includes the changes described in this advisory, refer to the NetEye Update Section in the User Guide.

Affected Products

All NetEye 4.x versions >= 4.38

References

Luca Tecchio

Luca Tecchio

Software Developer - IT System & Service Management Solutions at Würth IT Italy

Author

Luca Tecchio

Software Developer - IT System & Service Management Solutions at Würth IT Italy

Leave a Reply

Your email address will not be published. Required fields are marked *

Archive