Security patches + bugfixes
Release history
authentik releases
The authentication glue you need.
All releases
16 shown
MTLS cert handling + docs fix + freezegun config
- Added flag to skip migrations during lifecycle/migrate
- Updated security policy to include explicit intended functionality
- Added login_hint support for interactive authentication in enterprise agents
- Added wsfed to the application wizard
- Made gunicorn --max-requests configurable
Bug fix release for 2026.2 addressing WSFED metadata export, LDAP connection logging, provider resolution issues, and widget styling in compatibility mode. Includes HTTP timeout configurability.
- RBAC improvements
- expanded integrations
Maintenance release with multiple backported fixes from main branch covering flow handling, TLS configuration, database queries, SAML functionality, and proxy improvements.
- CVE-2026-25922
- CVE-2026-25748
- CVE-2026-25227
Fixed critical issues with toggle groups, brand CSS application, service account expiration, and data directory permissions. Reverted accidental bulk revoke feature.
Addressed critical bugs in SAML encryption, file management, forms, and session synchronization. Fixes enable proper handling of encrypted SAML assertions and correct form date handling.
Bug fix release addressing theming issues, API client generation, agent configuration, and various UI improvements across flows and forms.
Maintenance release with multiple bug fixes across documentation, endpoints, database replication, static tokens, and OAuth providers. Includes dependency updates and improved flow import guidance.