A substantial operator-focused release that adds and promotes APIs, feature gates, administration capabilities, and deployment options. It also includes deprecations and removals, along with fixes for account takeover, log injection and audit forgery, key-attestation bypass, QR-code dimension denial of service, and four CVE-identified vulnerabilities.
Action needed (1)
securityPre-account takeover attack exposure
The release corrects an issue that provided room for pre-account takeover attacks.
Check if affected (19)
securitymediumCVE-2026-9796, admin role rename authorization
Applies if you use
manage-clients.securitymediumCVE-2026-9689, OIDC redirect URI parameter handling
Applies if you use
OIDC.securitymediumCVE-2026-9798, CIBA account lockout
Applies if you run the
CIBAauthentication flow.- + 16 more on the release page
Plan ahead (4)
deprecatedThe
V1API, deprecatedApplies if you use
V1.deprecatedThe
Require Discoverable Credentialoption, deprecatedApplies if you configure the
Require Discoverable Credentialoption.deprecatedThe Twitter IDP implementation, deprecated
Applies if you use the Twitter IDP implementation.
- + 1 more on the release page