NetEye Product Security has rated this update as having a high security impact.
Topic
An update for the keycloak packages is now available for NetEye 4.
Security Fix for NetEye 4.50:
26.8.0_neteye1.47.1-1
Summary
This Keycloak update (version 26.8.0) resolves several security issues identified in upstream Keycloak, including those fixed in upstream release 26.7.5:
CVE-2026-16103: Incomplete fix for CVE-2026-9798 (CIBA brute-force lockout bypass at token redemption)
CVE-2026-88770: Device Authorization Grant issues tokens to brute-force-locked accounts
CVE-2026-18206: Client policy source-host wildcard domains match non-subdomain suffixes
CVE-2026-18203: Group policy child-extension matches sibling group path prefixes
CVE-2026-18207: Source-group condition matches duplicate group names and can skip negative-logic enforcement
CVE-2026-18208: Inactive out-of-audience introspection responses can include a signed JWT claim
CVE-2026-19608: Name-only group claims let same-name groups satisfy path-specific group policies
OIDC group synchronization with read-only LDAP federation Fixed an issue that occurred when OIDC group synchronization was enabled alongside a read-only LDAP federation. The OIDC mapper attempted to modify LDAP-managed group memberships, resulting in the error: Not possible to delete Read More
Important: GLPI security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the glpi packages is now available for NetEye 4. Security Fix for NetEye 4.50 glpi-11.0.11_neteye1.25.3-1 glpi-autosetup-11.0.11_neteye1.25.3-1 glpi-configurator-11.0.11_neteye1.25.3-1 glpi-neteye-config-11.0.11_neteye1.25.3-1 Summary This is Read More
NATS: Fix multi-tenancy configuration corruption in cluster environments When executing commands such as neteye install --restrict-services-to nats-server, neteye tenant config apply, or neteye satellite config create from a cluster node while nats-server was active on a different node, the shared Read More
Important: Grafana security update Type/Severity NetEye Product Security has rated this update as having a medium security impact. Topic An update for the grafana packages is now available for NetEye 4. Security Fix for NetEye 4.49 and 4.50 grafana-12.4.12_neteye3.31.4-1 Summary Four medium-severity CVEs Read More
Fixes for nginx and nginx-satellite We identified and fixed two issues affecting nginx resource management during service and resource restarts. nginx-satellite.service An issue could leave nginx worker processes running after nginx-satellite.service entered a failed state. These processes could continue listening Read More