Release Date: 8 October 2026

Release (1.15.6)

Patch release

  • All releases from Neo4j Ops Manager 1.15.0 and later require Neo4j persistence to be version 5.26 LTS or greater. 
  • Monitoring instances with versions of 4.4 LTS and greater is still supported, although 4.4 LTS is out of support with Neo4j.
See Version Compatibility Docs

Changes

For docker deployments of Neo4j Ops Manager, this release replaces all base docker images with appropriate distroless images for better security and smaller docker images. If you use docker for Neo4j Ops Manager please read about these breaking changes:
  • JAVA_OPTS no longer works for the server image. The distroless images have no shell, so the previous ENTRYPOINT ["sh", "-c", "java ${JAVA_OPTS} -jar app.jar $@"] could not be kept. The server ENTRYPOINT is now the exec-form ["java"] / CMD ["-jar", "app.jar"]. If you were passing extra JVM flags via a JAVA_OPTS environment variable, switch to JAVA_TOOL_OPTIONS instead — it is read natively by the JVM at startup and requires no shell:

before

docker run -e JAVA_OPTS="-Xmx2g -Dfoo=bar" ops-manager-server

after

docker run -e JAVA_TOOL_OPTIONS="-Xmx2g -Dfoo=bar" ops-manager-server

Note the JVM prints a one-line notice to stderr when JAVA_TOOL_OPTIONS is picked up (“Picked up JAVA_TOOL_OPTIONS: …”) — this is expected and harmless. Also, any extra positional arguments previously appended after the image name (the old $@ in the shell command) are no longer forwarded; pass additional java arguments only if you rebuild the image or extend CMD/ENTRYPOINT yourself.

  • No shell / package manager in the images. docker exec -it <container> sh (or bash) no longer works against the server, server-from-jar, agent, or agent-from-binaries images — there is no shell binary in them. If you need to inspect a running container interactively (e.g. for support/debugging), use docker cp to pull files out.

Internal

  • postcss-selector-parser to 6.1.4
  • to-fast-properties to 4.0.0
  • vitest to 4.1.11
  • @testing-library/jest-dom to 7.0.1
  • morgan to 1.12.1
  • ip-address to 10.7.2
  • undici to 7.30.0
  • moment to 2.31.0
 
  • spring-boot to 4.1.1
  • stretchr/testify to 1.12.1
  • pmd.version to 7.28.0
  • protobuf-java to 4.36.2
  • guava to 33.7.1-jre
  • jsoup to 1.23.2
  • json-schema-validator to 3.0.7
  • grpc to 1.84.0
  • neo4j-migrations-spring-boot-starter to 4.2.0
  • prometheus/client_model to 0.6.3
  • byte-buddy to 1.18.14
  • crypto to 0.57.0
  • prometheus/common to 0.71.0
  • bcpkix-jdk18on to 1.86
  • tomcat-embed-core to 11.0.26
  • nimbus-jose-jwt to 10.10
  • atomic to 1.12.0
  • mockito-core to 5.24.0
  • neo4j-go-driver/v5 to 5.28.5
  • caffeine to 3.3.0
  • org.apache.commons:commons-lang3 to 3.21.0

Known issues

There are still some known vulnerabilities in the docker base image (debian 13.7) for :
    • CVE-2026-66046
    • CVE-2026-76956
    • CVE-2026-76957
    • CVE-2026-93990
    • CVE-2026-76642
    • CVE-2026-78408
    • CVE-2026-78409
    • CVE-2026-78410
The Neo4j Ops Manager image is not necessarily vulnerable just because those CVEs exist in the base image. Further patches will be made available once fixes are provided.