Release Date: 8 October 2026
Release (1.15.6)
Patch release
- All releases from Neo4j Ops Manager 1.15.0 and later require Neo4j persistence to be version 5.26 LTS or greater.
- Monitoring instances with versions of 4.4 LTS and greater is still supported, although 4.4 LTS is out of support with Neo4j.
Changes
For docker deployments of Neo4j Ops Manager, this release replaces all base docker images with appropriate distroless images for better security and smaller docker images. If you use docker for Neo4j Ops Manager please read about these breaking changes:- JAVA_OPTS no longer works for the server image. The distroless images have no shell, so the previous ENTRYPOINT
["sh", "-c", "java ${JAVA_OPTS} -jar app.jar $@"]could not be kept. The server ENTRYPOINT is now the exec-form["java"] / CMD ["-jar", "app.jar"]. If you were passing extra JVM flags via a JAVA_OPTS environment variable, switch to JAVA_TOOL_OPTIONS instead — it is read natively by the JVM at startup and requires no shell:
before
docker run -e JAVA_OPTS="-Xmx2g -Dfoo=bar" ops-manager-server
after
docker run -e JAVA_TOOL_OPTIONS="-Xmx2g -Dfoo=bar" ops-manager-server
Note the JVM prints a one-line notice to stderr when JAVA_TOOL_OPTIONS is picked up (“Picked up JAVA_TOOL_OPTIONS: …”) — this is expected and harmless. Also, any extra positional arguments previously appended after the image name (the old $@ in the shell command) are no longer forwarded; pass additional java arguments only if you rebuild the image or extend CMD/ENTRYPOINT yourself.
- No shell / package manager in the images. docker exec -it <container> sh (or bash) no longer works against the server, server-from-jar, agent, or agent-from-binaries images — there is no shell binary in them. If you need to inspect a running container interactively (e.g. for support/debugging), use docker cp to pull files out.
Internal
- postcss-selector-parser to 6.1.4
- to-fast-properties to 4.0.0
- vitest to 4.1.11
- @testing-library/jest-dom to 7.0.1
- morgan to 1.12.1
- ip-address to 10.7.2
- undici to 7.30.0
- moment to 2.31.0
- spring-boot to 4.1.1
- stretchr/testify to 1.12.1
- pmd.version to 7.28.0
- protobuf-java to 4.36.2
- guava to 33.7.1-jre
- jsoup to 1.23.2
- json-schema-validator to 3.0.7
- grpc to 1.84.0
- neo4j-migrations-spring-boot-starter to 4.2.0
- prometheus/client_model to 0.6.3
- byte-buddy to 1.18.14
- crypto to 0.57.0
- prometheus/common to 0.71.0
- bcpkix-jdk18on to 1.86
- tomcat-embed-core to 11.0.26
- nimbus-jose-jwt to 10.10
- atomic to 1.12.0
- mockito-core to 5.24.0
- neo4j-go-driver/v5 to 5.28.5
- caffeine to 3.3.0
- org.apache.commons:commons-lang3 to 3.21.0
Known issues
There are still some known vulnerabilities in the docker base image (debian 13.7) for :-
- CVE-2026-66046
- CVE-2026-76956
- CVE-2026-76957
- CVE-2026-93990
- CVE-2026-76642
- CVE-2026-78408
- CVE-2026-78409
- CVE-2026-78410
The Neo4j Ops Manager image is not necessarily vulnerable just because those CVEs exist in the base image. Further patches will be made available once fixes are provided.
Recent Neo4j Operations Manager Releases
- Neo4j Ops Manager 1.15.6
- Neo4j Ops Manager 1.15.5
- Neo4j Ops Manager 1.15.3
- Neo4j Ops Manager 1.15.2
- Neo4j Ops Manager 1.15.1