01. 10. 2026 Damiano Chini Bug Fixes, NetEye

NetEye 4 – Security Advisory (Grafana)

Important: Grafana security update

Type/Severity

NetEye Product Security has rated this update as having a medium security impact.

Topic

An update for the grafana packages is now available for NetEye 4.

Security Fix for NetEye 4.49 and 4.50

  • grafana-12.4.12_neteye3.31.4-1

Summary

Four medium-severity CVEs were fixed (CVSS 4.3–5.4). Three concern permission scoping: alert rules listable from folders a user may not read (CVE-2026-13719), an Editor able to mark a dashboard as file-provisioned so admins can no longer change or delete it (CVE-2026-13720), and edit rights on one folder allowing dashboards to be moved beyond that scope (CVE-2026-81842). The fourth fixes paused public dashboards keeping a valid access token, letting anyone with the link read dashboard configuration unauthenticated (CVE-2026-81841).

For details on how to apply this update, which includes the changes described in this advisory, refer to the NetEye Update Section in the User Guide.

Affected Products

All NetEye 4.x versions

References

Damiano Chini

Damiano Chini

Author

Damiano Chini

Leave a Reply

Your email address will not be published. Required fields are marked *

Archive