Skip to content

authentik

version/2026.2.6 Security

This release includes 5 security fixes for security teams reviewing exposed deployments.

Published 11d Secrets & Credentials
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 5 known CVEs

Topics

authentication authentik authorization kubernetes oauth2 oauth2-client
+10 more
oauth2-server oidc oidc-client oidc-provider proxy saml saml-idp saml-sp security sso

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 11d

Version 2026.2.6 of authentik backports multiple security patches to the core product and resolves several bug‑fixes across sync, OAuth, and Django broker components.

Why it matters: The release applies high‑severity (90) security patches to authentik core; operators should upgrade immediately to mitigate identified vulnerabilities.

Summary

AI summary

Updates tests/openid_conformance, lib/sync/outgoing, and sources/oauth across a mixed release.

Changes in this release

Security Critical

Backports multiple security patches to authentik-2026.2.

Backports multiple security patches to authentik-2026.2.

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Fixes discover running for each page in lib/sync/outgoing.

Fixes discover running for each page in lib/sync/outgoing.

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Improves id_token validation for Apple OAuth source.

Improves id_token validation for Apple OAuth source.

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Closes unusable PostgreSQL connections in django-dramatiq-postgres broker.

Closes unusable PostgreSQL connections in django-dramatiq-postgres broker.

Source: llm_adapter@2026-07-15

Confidence: high

Full changelog

See https://docs.goauthentik.io/docs/releases/2026.2#fixed-in-202626

What's Changed

  • tests/openid_conformance: migrate to upstream images (cherry-pick #23828 to version-2026.2) by @authentik-cherry-pick[bot] in https://github.com/goauthentik/authentik/pull/23835
  • lib/sync/outgoing: fix discover running for each page (cherry-pick #24016 to version-2026.2) by @authentik-cherry-pick[bot] in https://github.com/goauthentik/authentik/pull/24018
  • sources/oauth: improve id_token validation for apple source (cherry-pick #24017 to version-2026.2) by @authentik-cherry-pick[bot] in https://github.com/goauthentik/authentik/pull/24021
  • packages/django-dramatiq-postgres/broker: close unusable PostgreSQL connections (cherry-pick #24023 to version-2026.2) by @authentik-cherry-pick[bot] in https://github.com/goauthentik/authentik/pull/24034
  • security: automated internal backport of patch 1919.sec.patch to authentik-2026.2 by @authentik-automation[bot] in https://github.com/goauthentik/authentik/pull/24056
  • security: automated internal backport of patch 1822.sec.patch to authentik-2026.2 by @authentik-automation[bot] in https://github.com/goauthentik/authentik/pull/24054
  • security: automated internal backport of patch 1934.sec.patch to authentik-2026.2 by @authentik-automation[bot] in https://github.com/goauthentik/authentik/pull/24057
  • security: automated internal backport of patch 1887.sec.patch to authentik-2026.2 by @authentik-automation[bot] in https://github.com/goauthentik/authentik/pull/24055
  • security: automated internal backport of patch 1817.sec.patch to authentik-2026.2 by @authentik-automation[bot] in https://github.com/goauthentik/authentik/pull/24053
  • website/docs: release notes for 2026.2.6 (cherry-pick #24069 to version-2026.2) by @authentik-cherry-pick[bot] in https://github.com/goauthentik/authentik/pull/24072

Full Changelog: https://github.com/goauthentik/authentik/compare/version/2026.2.5...version/2026.2.6

Security Fixes

  • Automated internal backport of patch 1919.sec.patch
  • Automated internal backport of patch 1822.sec.patch
  • Automated internal backport of patch 1934.sec.patch
  • Automated internal backport of patch 1887.sec.patch
  • Automated internal backport of patch 1817.sec.patch

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track authentik

Get notified when new releases ship.

Sign up free

About authentik

The authentication glue you need.

All releases →

Beta — feedback welcome: [email protected]