Most of the 36 CVEs are Denial of Service vulnerabilities affecting Elasticsearch (uncontrolled recursion in intervals queries/wildcard matching/analysis definitions, memory allocation without limits in search/highlighting) and Kibana (TSVB, connector reporting, alerting, case management, Observability log analysis, CSRF via Vega visualizations), within the Elastic Stack. The remaining CVEs relate to authorization and access control weaknesses in Kibana and Fleet Server, including Missing/Incorrect Authorization (Agent Builder privilege escalation and data tampering, Elastic Defend endpoint response actions information disclosure, cross-space access to Machine Learning trained models, unauthorized execution of Osquery/Endpoint response actions), Authorization Bypass Through User-Controlled Key (Fleet Elastic Agent API key disclosure, cross-space alerting telemetry and ML disclosure), Code Injection in Fleet Server, and an Out-of-range Pointer Offset in the Elasticsearch Machine Learning native inference process, that can lead to unauthorized information disclosure, privilege escalation, data tampering or remote code execution.
Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a High security impact. Topic Updates for the Elastic Stack packages are now available for NetEye 4. Security Fix for NetEye 4.49 9.4.6_neteye3.103.8-1 CVEs Elastic Read More
Historical log data is valuable—until the cost of keeping every shard online starts competing with the value of the data itself. Elasticsearch searchable snapshots offer a practical middle ground for a NetEye installation: keep an index in a snapshot repository, Read More
Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a critical security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.49 26.7.2_neteye1.46.1-1 Summary This vulnerability, tracked as CVE-2026-18963 Read More
Important: Icinga 2 security update Type/Severity NetEye Product Security has rated this update as having a medium security impact. Topic An update for the icinga package is now available for NetEye 4. Security Fix for NetEye 4.49 2.15.6_neteye1.73.1-1 Summary This release fixes authorization Read More
RKE2 Otel Collector DNS requirement During updates and first installations on systems where the Elastic Stack feature module was installed, an extra requirement was present. In particular, the DNS defined in the resolv.conf of the machine was required to resolve Read More