Is it safe to update Authentik?

Tracking goauthentik/authentik

Safe to update.

The release notes describe only bug fixes, a dependency security bump, and documentation improvements — no breaking changes, required migrations, or manual upgrade steps are called out. The two CVEs make applying this patch advisable promptly, but nothing in the notes indicates operator action beyond a standard update.

Latest version
version/2026.5.3
Last checked

What changed

version/2026.5.3 is a patch release focused on bug fixes and security updates. Notable repairs include a fix for SCIM's interactive OAuth incorrectly overriding refresh tokens, a panic in the RADIUS provider log, and an exception in the endpoints/connectors agent when encountering an invalid auth type. The Docker outpost integration form's CA certificate filter is corrected, blueprint application now handles integrity exceptions gracefully, and a polyfill is added for Safari versions below 17.4. Two CVEs (CVE-2026-49443 and CVE-2026-49448) are addressed, and the Django dependency is bumped to v5.2.15.

Source

Every verdict on Bumplog traces back to a GitHub release. No invented details.