07. 10. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4 – Security Advisory (Elastic Stack)

Important: Elastic Stack security update

Type/Severity

NetEye Product Security has rated this update as having a High security impact.

Topic

Updates for the Elastic Stack packages are now available for NetEye 4.

Security Fix for NetEye 4.50

  • 9.5.5_neteye3.105.3-1

CVEs

Elastic Agent

  1. CVE-2026-102413
    CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Elasticsearch

  1. CVE-2026-103009
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
  2. CVE-2026-103008
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  3. CVE-2026-103005
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  4. CVE-2026-102409
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  5. CVE-2026-102404
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  6. CVE-2026-102408
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Kibana

  1. CVE-2026-102412
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Most of the 8 CVEs are resource-exhaustion weaknesses in Elasticsearch. These are Uncontrolled Recursion, Uncontrolled Resource Consumption, Memory Allocation with Excessive Size Value, and Inefficient Regular Expression Complexity, found in scripted geometry runtime fields, the Connector API, and the ES|QL query engine and its CHUNK function. They let a low-privileged authenticated user crash a node or degrade it. Elasticsearch is also affected by an Authorization Bypass Through User-Controlled Key in cross-cluster search with the RCS 2.0 model, which can expose the contents of unauthorized indices. The remaining CVEs are an Incorrect Authorization in Kibana, which lets users with limited Fleet privileges get the SSL private keys of Fleet Server hosts, and an Uncaught Exception in Elastic Endpoint, which can repeatedly crash Elastic Defend on Windows hosts with CJK locales. Together, these CVEs can lead to unauthorized information disclosure, credential exposure, or denial of service.

Affected Products

All NetEye 4.x versions >= 4.25.

References

Patrick Harasser

Patrick Harasser

Author

Patrick Harasser

Leave a Reply

Your email address will not be published. Required fields are marked *

Archive