This release includes 5 security fixes for security teams reviewing exposed deployments.
Topics
+10 more
Affected surfaces
ReleasePort's take
Moderate signalVersion 2026.2.6 of authentik backports multiple security patches to the core product and resolves several bug‑fixes across sync, OAuth, and Django broker components.
Why it matters: The release applies high‑severity (90) security patches to authentik core; operators should upgrade immediately to mitigate identified vulnerabilities.
Summary
AI summaryUpdates tests/openid_conformance, lib/sync/outgoing, and sources/oauth across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Backports multiple security patches to authentik-2026.2. Backports multiple security patches to authentik-2026.2. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes discover running for each page in lib/sync/outgoing. Fixes discover running for each page in lib/sync/outgoing. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Improves id_token validation for Apple OAuth source. Improves id_token validation for Apple OAuth source. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Closes unusable PostgreSQL connections in django-dramatiq-postgres broker. Closes unusable PostgreSQL connections in django-dramatiq-postgres broker. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
See https://docs.goauthentik.io/docs/releases/2026.2#fixed-in-202626
What's Changed
- tests/openid_conformance: migrate to upstream images (cherry-pick #23828 to version-2026.2) by @authentik-cherry-pick[bot] in https://github.com/goauthentik/authentik/pull/23835
- lib/sync/outgoing: fix discover running for each page (cherry-pick #24016 to version-2026.2) by @authentik-cherry-pick[bot] in https://github.com/goauthentik/authentik/pull/24018
- sources/oauth: improve id_token validation for apple source (cherry-pick #24017 to version-2026.2) by @authentik-cherry-pick[bot] in https://github.com/goauthentik/authentik/pull/24021
- packages/django-dramatiq-postgres/broker: close unusable PostgreSQL connections (cherry-pick #24023 to version-2026.2) by @authentik-cherry-pick[bot] in https://github.com/goauthentik/authentik/pull/24034
- security: automated internal backport of patch 1919.sec.patch to authentik-2026.2 by @authentik-automation[bot] in https://github.com/goauthentik/authentik/pull/24056
- security: automated internal backport of patch 1822.sec.patch to authentik-2026.2 by @authentik-automation[bot] in https://github.com/goauthentik/authentik/pull/24054
- security: automated internal backport of patch 1934.sec.patch to authentik-2026.2 by @authentik-automation[bot] in https://github.com/goauthentik/authentik/pull/24057
- security: automated internal backport of patch 1887.sec.patch to authentik-2026.2 by @authentik-automation[bot] in https://github.com/goauthentik/authentik/pull/24055
- security: automated internal backport of patch 1817.sec.patch to authentik-2026.2 by @authentik-automation[bot] in https://github.com/goauthentik/authentik/pull/24053
- website/docs: release notes for 2026.2.6 (cherry-pick #24069 to version-2026.2) by @authentik-cherry-pick[bot] in https://github.com/goauthentik/authentik/pull/24072
Full Changelog: https://github.com/goauthentik/authentik/compare/version/2026.2.5...version/2026.2.6
Security Fixes
- Automated internal backport of patch 1919.sec.patch
- Automated internal backport of patch 1822.sec.patch
- Automated internal backport of patch 1934.sec.patch
- Automated internal backport of patch 1887.sec.patch
- Automated internal backport of patch 1817.sec.patch
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]