AK

authentik 2026.8.2

Get release alerts
2026.8.1โ†’2026.8.2SecurityBug fix
๐Ÿ“… September 9, 2026๐Ÿ—‚ Security๐Ÿ“ฆ authentik โ†—๐Ÿ“œ Full changelog โ†—
โœฆ Editor's summary

authentik 2026.8.2 is a security and maintenance release for the 2026.8 branch. It includes five security-related backports and fixes issues affecting authentication backends, bulk session revocation, RBAC object permissions, policy execution, scheduled tasks, Prometheus metrics, tenant settings, and the administrative interface.

โš  Security impact
  • Includes multiple internal security patch backports affecting secrets read permissions, group hierarchy roles, SAML processing, authenticator email recipient handling, and XML/libxml2 DOCTYPE processing.
  • Authentication backends now explicitly verify that users are active before authentication is allowed.
  • Includes security hardening for authorization and identity-related functionality.

What's new

authentik 2026.8.2 is a security and maintenance update focused on authentication security, session management, authorization, reliability, and administrative interface fixes.

What's new
  • Improves authentication security by explicitly checking whether users are active in authentication backends.
  • Fixes bulk session revocation to ensure sessions are correctly terminated when requested.
  • Fixes RBAC object permission handling when the referenced object no longer exists.
  • Fixes a PickleError that could occur when using ak_call_policy in expression policies.
  • Prevents unnecessary DNS resolution when generating randomized FQDN values.
  • Fixes Prometheus server metrics being registered with the process ID instead of the correct worker ID.
  • Prevents scheduled-task consumer threads from crashing when encountering schedules referencing unknown actors.
  • Fixes tenant settings flag responses and several administrative interface issues.
  • Fixes schedule forms, command palette navigation, table toolbar switches, custom event action labels, and paginated search-select values.
  • Includes multiple internal security patch backports covering permissions, SAML, authentication, and XML processing.
Recommendation

Organizations running authentik 2026.8.0 or 2026.8.1 should prioritize upgrading to 2026.8.2 after standard validation due to the included security patches and authentication and session-management fixes. Ensure that authentik servers, workers, and outposts are upgraded to matching versions.

More from authentik
authentik 2026.8.0FeatureBreakingBug fixPerformanceAug 18, 2026
Latest in Security
Vaultwarden: Vaultwarden 1.37.3SecurityFeatureBug fixSep 13, 2026
JumpServer: JumpServer v4.10.19 LTSSecurityBug fixPerformanceAug 20, 2026

๐Ÿ’ฌ Comments (0)

Have you installed this authentik update?

Share any installation issues, compatibility changes, or fixes you noticed.