Is it safe to update Authentik?
Tracking goauthentik/authentik
Safe to update.
The release notes describe only bug fixes, a dependency security bump, and documentation improvements — no breaking changes, required migrations, or manual upgrade steps are called out. The two CVEs make applying this patch advisable promptly, but nothing in the notes indicates operator action beyond a standard update.
What changed
version/2026.5.3 is a patch release focused on bug fixes and security updates. Notable repairs include a fix for SCIM's interactive OAuth incorrectly overriding refresh tokens, a panic in the RADIUS provider log, and an exception in the endpoints/connectors agent when encountering an invalid auth type. The Docker outpost integration form's CA certificate filter is corrected, blueprint application now handles integrity exceptions gracefully, and a polyfill is added for Safari versions below 17.4. Two CVEs (CVE-2026-49443 and CVE-2026-49448) are addressed, and the Django dependency is bumped to v5.2.15.
Source
Every verdict on Bumplog traces back to a GitHub release. No invented details.