Release of authentik Security releases 2025.8.6, 2025.10.4 and 2025.12.4

2 views
Skip to first unread message

authentik Security Announcements

unread,
Feb 17, 2026, 1:50:43 PM (yesterday) Feb 17
to authentik Security Announcements
The security advisory for CVE-2026-25922 has been published: https://github.com/goauthentik/authentik/security/advisories/GHSA-jh35-c4cc-wjm4
The security advisory for CVE-2026-25227 has been published: https://github.com/goauthentik/authentik/security/advisories/GHSA-qvxx-mfm6-626f
The security advisory for CVE-2026-25748 has been published: https://github.com/goauthentik/authentik/security/advisories/GHSA-fj56-5763-j8pp

CVE-2026-25886 has been dropped as we've deemed it not exploitable without prior attacker control, and we will be adding features in the future to make the corresponding behavior configurable.

Releases 2025.8.6, 2025.10.4 and 2025.12.4 with fixes included are available here:

 - https://github.com/goauthentik/authentik/releases/tag/version%2F2025.8.6 (for 2025.8.6)
 - https://github.com/goauthentik/authentik/releases/tag/version%2F2025.10.4 (for 2025.10.4)
 - https://github.com/goauthentik/authentik/releases/tag/version%2F2025.12.4 (for 2025.12.4)
Reply all
Reply to author
Forward
0 new messages