authentik 2026.8.2
authentik 2026.8.2 is a security and maintenance release for the 2026.8 branch. It includes five security-related backports and fixes issues affecting authentication backends, bulk session revocation, RBAC object permissions, policy execution, scheduled tasks, Prometheus metrics, tenant settings, and the administrative interface.
- Includes multiple internal security patch backports affecting secrets read permissions, group hierarchy roles, SAML processing, authenticator email recipient handling, and XML/libxml2 DOCTYPE processing.
- Authentication backends now explicitly verify that users are active before authentication is allowed.
- Includes security hardening for authorization and identity-related functionality.
What's new
authentik 2026.8.2 is a security and maintenance update focused on authentication security, session management, authorization, reliability, and administrative interface fixes.
What's new- Improves authentication security by explicitly checking whether users are active in authentication backends.
- Fixes bulk session revocation to ensure sessions are correctly terminated when requested.
- Fixes RBAC object permission handling when the referenced object no longer exists.
- Fixes a PickleError that could occur when using ak_call_policy in expression policies.
- Prevents unnecessary DNS resolution when generating randomized FQDN values.
- Fixes Prometheus server metrics being registered with the process ID instead of the correct worker ID.
- Prevents scheduled-task consumer threads from crashing when encountering schedules referencing unknown actors.
- Fixes tenant settings flag responses and several administrative interface issues.
- Fixes schedule forms, command palette navigation, table toolbar switches, custom event action labels, and paginated search-select values.
- Includes multiple internal security patch backports covering permissions, SAML, authentication, and XML processing.
Organizations running authentik 2026.8.0 or 2026.8.1 should prioritize upgrading to 2026.8.2 after standard validation due to the included security patches and authentication and session-management fixes. Ensure that authentik servers, workers, and outposts are upgraded to matching versions.
๐ฌ Comments (0)
Share any installation issues, compatibility changes, or fixes you noticed.