Password and Secrets Management Release Notes
Release notes for password managers and secrets management tools
Products (16)
Latest Password and Secrets Management Updates
- Sep 2, 2026
- Date parsed from source:Sep 2, 2026
- First seen by Releasebot:Sep 2, 2026
Bitwarden Clients by Bitwarden
Web v2026.8.1
Bitwarden Clients ships a broad update with new browser autofill for SSH keys, Open Org Invite Link support, improved Vault and Health views, and desktop autofill refinements for FIDO2 and native user verification. It also brings bug fixes, terminology updates, and crypto and dependency maintenance.
What's Changed
💙 Community Highlight
[PM-41559] [PM-41539] Recognize both Keeper SSO callback URL forms by @detunized in #22265
[PM-41979] [PM-41899] [VULN-735] Validate profileId in Chromium importer by @detunized in #22432
[PM-29036] fix(desktop): set desktopName for Wayland app_id to display correct icon by @thisisryanswift in #17764
[PM-38964] Remove obsolete LockScreen config from AppX manifest by @hammadxcm in #21229Feature Development
[PM-40945] add testing to relevant components by @dan-livefront in #22224
feat(browser): Add autofill for SSH keys by @quexten in #21289
Auth/PM-39706 - Open Org Invite Link Support by @JaredSnider-Bitwarden in #21574
[PM-40736] billing terminology update by @JaredScar in #22114
[PM-32211] fix private key before key rotation by @mzieniukbw in #20392
[PM-35945] Browser: Show the Health Overview after a scan (gauge and risk categories) by @AlexRubik in #22235
Auth / PM-41503 & PM-41533 - Registration - Wire new open org invite data into register start and finish by @JaredSnider-Bitwarden in #22333
[PM-41686]Implement plumbing for inline menu lit components by @dan-livefront in #22286
[CL-1210] use overflow directive to pack primary actions when needed by @BryanCunningham in #21589
Feature/webmapper integration by @blackwood in #21738
desktop-autofill: Refactor UV reprompt and window management [PM-29791] by @iinuwa in #22257
[PM-40312] Introduce vault items table component by @shane-melton in #22237
[CL-1245] updated icon tile colors by @BryanCunningham in #22102
[PM-40330] Add vault list table to desktop behind VFO1Foundation flag by @nick-livefront in #22383
desktop-autofill: Define the desktop FIDO2 user verification service [PM-29791] by @iinuwa in #22258
[CL-1237] sidenav updates by @BryanCunningham in #21855
[PM-35946] Browser: Health report at risk category detail view by @lastbestdev in #22246
PM-40304: Add the conditional Vaults nav-section logic and vault-type color mapping by @nikwithak in #22119
desktop-autofill: Implement FIDO2 user verification logic [PM-29791] by @iinuwa in #22259
VaultPopupListTableComponent + Storybook by @nick-livefront in #22106
[CL-998] table-v2 polish by @willmartian in #22255
[PM-41902] Member Access Report terminology changes by @JaredScar in #22410
[PM-40212] Enable-PAM UI (member toggle + bulk Activate PAM) by @Hinton in #22478
[PM-37839] Browser: Delete item from at risk category view by @lastbestdev in #22268
[PM-41687]Implement locked and saved login lit components by @dan-livefront in #22348
[PM-40318] Introduce Web's VaultNextComponet for VFO1 by @shane-melton in #22425
[PM-34808] Step 1 remove flagged logic for policy drawers by @JaredScar in #22342
Browser: Add dark mode image to Health tab intro CTA by @lastbestdev in #22487
[PM-36628] Browser: Add clean state to Health at risk category detail view by @lastbestdev in #22396
desktop-autofill: Verify user without UI on assertion when possible [PM-29791] by @iinuwa in #22177
desktop-autofill: macOS native user verification [PM-29791] by @iinuwa in #22178
desktop-autofill: Windows native user verification [PM-29791] by @iinuwa in #22179
desktop-autofill: Refactor FIDO2 modals by @iinuwa in #22433
[PM-41688] Implement cipher list lit components by @dan-livefront in #22378
desktop-autofill: Skip registration confirmation by @iinuwa in #22435
[PM-40395] Add Import button to new vault table by @nikwithak in #22439
[PM-39455] Use v2 upgrade token when asserting organization public key trust. by @mzieniukbw in #22490
[PM-40127] Item history redesign using bit-card-segmented by @nick-livefront in #21940
[PM-40333] Hide side-nav vault filter on desktop by @nick-livefront in #22434
[PM-40331] Vault Param Redirect by @nick-livefront in #22438
desktop-autofill: FIDO2 selection modal UI improvements by @iinuwa in #22436
[PM-41856] Update tooltip wording for icons by @jengstrom-bw in #22345
[PM-39408] feat: Tee TS logs into LogRecorder sink by @dani-garcia in #22379
[PM-40814] Add key id support by @quexten in #22444
Fix/late hydration shadow detection by @blackwood in #21370
[PM-41949] Enhance SecretsManagerSubscribeComponent with feature flag support by @JaredScar in #22412
[PM-40313] Restructure the Password Manager side navigation (web) by @gbubemismith in #22283
[PM-41472] feat(web): add the My folders page by @gbubemismith in #22267
[CL-1248] Add FAB button component to vault by @nick-livefront in #22523
[PM-41273] Extend ImportService to expose per-vendor metadata by @harr1424 in #22297
[PM-40740] Policies list & drawers terminology updates by @JaredScar in #22377
[CL-1194] responsive breadcrumbs by @BryanCunningham in #21742
[PM-40318] VFO1 Web vault query param handling by @shane-melton in #22501
[PM-42183] VFO1 Side nav vault scoping by @shane-melton in #22567
Add desktop beta icons by @trmartin4 in #22445
[PM-39223] Browser: Run the vault scan and show its progress and failure states by @AlexRubik in #22346
[CL-988] Update no items component to status lockup design by @vleague2 in #22386
[PM-40848] Add the shared folder card grid component (libs/vault) by @jengstrom-bw in #22390🐛 Bug fixes
[PM-8711] inconsistent casing between vault management api feedback and api docs by @JaredScar in #22232
[PM-11607] AC Event Log Buttons vertical alignment by @JaredScar in #22222
[PM-41691] Fix issue where edit item, hidden passwords wipes password, TOTP by @JaredScar in #22287
[PM-40258]: AuthRequestResponse refactor by @enmande in #22182
[PM-41854] fix: skip collections coachmark step for users without collections by @gbubemismith in #22376
Auth/ PM-41535 & PM-41897 - Open Org Invite Link - Update accept-error classifier for new SDK API error format by @JaredSnider-Bitwarden in #22393
Auth & KM / PM-41538 - Organization Invite Acceptance - Show invite accepted toast on TDE and KC SSO JIT flows by @JaredSnider-Bitwarden in #22394
[PM-41880] Quick fix for edit members dialog dependencies by @ttalty in #22407
fix(biometrics): change the biometric persistent encryption migration to handle the case where the aes-cbc-hmac key has a key id by @quexten in #22336
[PM-41829] Login Buttons Overlap Owner and Name Elements When Resizing Browser by @jengstrom-bw in #22418
Auth/PM-41978 - Open Org Invite Acceptance - update error copy for vfo1-foundation vault terminology change by @JaredSnider-Bitwarden in #22485
[PM-42166] Update member access report terminology by @JaredScar in #22522
[PM-42006] Self Host Premium Upgrade Copy Change by @JaredScar in #22493
[PM-41830] Shrinking Window Causes Buttons to Overlap Owner Element and Pushes More Options Menu Offscreen by @jengstrom-bw in #22419
Auth / PM-32421 - CLI - Login Command - Validate SSO account has a CLI-supported decryption path by @JaredSnider-Bitwarden in #22411
[PM-42235] Browser: Health at risk category empty state fixes by @lastbestdev in #22538
[PM-42239] Access Intelligence: Match v2 request password change button behavior to v1 by @lastbestdev in #22537
[PM-40350] Revert early return introduced in #21836 by @harr1424 in #22453
[PM-41905] Add Autotype MVP Window Validity Check by @coltonhurst in #22398
Revert "[PM-42239] Access Intelligence: Match v2 request password change button behavior to v1" by @lastbestdev in #22590
fix(key-connector): fix sdk-based unlock with key-connector on jit provisioning by @quexten in #22545
[PM-42470] Add cooldown to user key id backfill migration (#22682) by @quexten in #22750
🍒 [PM-42443] Include member items when fetching org ciphers in Access Intelligence by @Banrion in #22751⚙️ Maintenance
chore: remove grype scanning by @sognefej in #22289
[chore] Add CODEOWNERS entry for the licensed browser DIRT directory by @AlexRubik in #22325
Autosync Crowdin Translations for web by @bw-ghapp[bot] in #22302
Autosync Crowdin Translations for desktop by @bw-ghapp[bot] in #22300
Autosync Crowdin Translations for browser by @bw-ghapp[bot] in #22301
Autosync Crowdin Translations for web by @bw-ghapp[bot] in #22340
Autosync Crowdin Translations for desktop by @bw-ghapp[bot] in #22338
Autosync Crowdin Translations for browser by @bw-ghapp[bot] in #22339
[PM-38767] Adopt cargo-run-bin for binary tool version pinning in desktop_native by @coroiu in #21169
refactor(crypto): split out legacy compat key service by @quexten in #22319
Add PAM Allium specification by @abergs in #22373
[PM-41874] refactor(crypto): move shared client wiring callers to @bitwarden/legacy-crypto by @quexten in #22368
[PM-41874] refactor(crypto): move dirt callers to @bitwarden/legacy-crypto by @quexten in #22366
[PM-41874] refactor(crypto): move admin-console callers to @bitwarden/legacy-crypto by @quexten in #22367
[PM-41874] refactor(crypto): move desktop-native callers to @bitwarden/legacy-crypto by @quexten in #22372
refactor(auth): unlock via UnlockService in login strategies by @quexten in #22354
[PM-36409] Enhance type safety across various components by @JaredScar in #22391
Remove unused loginApprovalModelRef by @djsmith85 in #22405
[PM-41874] refactor(crypto): move key-management callers to @bitwarden/legacy-crypto by @quexten in #22362
Autosync Crowdin Translations for browser by @bw-ghapp[bot] in #22423
Autosync Crowdin Translations for desktop by @bw-ghapp[bot] in #22422
Autosync Crowdin Translations for web by @bw-ghapp[bot] in #22424
[PM-35785] Fix SDK breaking change: missing asUuid by @eliykat in #22392
refactor(key-management-ui): stop re-setting the user key after unlock by @quexten in #22355
[BRE-2116] Bump actions/checkout to v7.0.1 + add bypass flag in client build workflows by @brandonbiete in #22385
Fix: breaking SDK change - use asUuid in tests by @eliykat in #22443
widen engines pin to include Node 24 by @addisonbeck in #22480
[PM-38455] Remove unused premiumRequired from app.components by @djsmith85 in #22403
[PM-41874] refactor(crypto): move tools callers to @bitwarden/legacy-crypto by @quexten in #22364
[PM-41874] refactor(crypto): move secrets-manager callers to @bitwarden/legacy-crypto by @quexten in #22370
[PM-41874] refactor(crypto): move platform callers to @bitwarden/legacy-crypto by @quexten in #22369
[PM-41874] refactor(crypto): move vault callers to @bitwarden/legacy-crypto by @quexten in #22365
[PM-41684] Remove unused Autotype MVP IPC channels by @coltonhurst in #22285
[PM-41801] Switch to using policyAppliesToUser$ for the Autotype Default Policy by @coltonhurst in #22322
[PM-42196] Update Native Passkey Ownership by @coltonhurst in #22529
refactor(auth): unlock via UnlockService when setting an initial password by @quexten in #22356
[PM-41874] refactor(crypto): move billing callers to @bitwarden/legacy-crypto by @quexten in #22371
[PM-41874] refactor(crypto): move auth callers to @bitwarden/legacy-crypto by @quexten in #22363
refactor(key-management): read the user key via userKey$ by @quexten in #22353
refactor(unlock): replace UserAutoUnlockKeyService with UnlockService by @quexten in #22359
refactor(key-management): unlock via UnlockService in key connector conversion by @quexten in #22358
[PM-41874] Remove legacy-crypto shims (platform) by @quexten in #22579
chore(lock): Move LockService into libs/unlock and add lock/unlock source tracking by @quexten in #22539
[PM-41874] Remove legacy-crypto shims (key management) by @quexten in #22578
ci: Beta Appx manifest changes by @iinuwa in #22564
Autosync Crowdin Translations for desktop by @bw-ghapp[bot] in #22568
Autosync Crowdin Translations for browser by @bw-ghapp[bot] in #22569
refactor(auth): unlock via UnlockService during TDE JIT registration by @quexten in #22357
Autosync Crowdin Translations for web by @bw-ghapp[bot] in #22570
Autosync Crowdin Translations for web by @bw-ghapp[bot] in #22607
refactor(crypto): drop electron key service by @quexten in #22601
Sign Windows Beta Appx in CI by @iinuwa in #22563
[PM-38187] Improve isSnapStore detection by @djsmith85 in #21195
Bump client version(s) by @github-actions[bot] in #22608📦 Dependency Updates
Update sdk-internal to 0.2.0-main.956 by @bw-ghapp[bot] in #22146
[deps] Platform: Update @types/node to v22.20.1 by @renovate[bot] in #22218
Update sdk-internal to 0.2.0-main.967 by @bw-ghapp[bot] in #22326
[deps]: Update dtolnay/rust-toolchain digest to 4360b52 by @renovate[bot] in #22459
[deps]: Update actions/stale action to v11 by @renovate[bot] in #22475
Update sdk-internal to 0.2.0-main.970 by @bw-ghapp[bot] in #22442
Update sdk-internal to 0.2.0-main.971 by @bw-ghapp[bot] in #22512
[deps] Desktop Native: Update Rust crate serial_test to v4 by @renovate[bot] in #22469
[deps] Platform: Update Rust crate serde_with to v3.22.0 by @renovate[bot] in #22462
[deps]: Update Rust to v1.97.1 by @renovate[bot] in #22467
Update sdk-internal to 0.2.0-main.978 by @bw-ghapp[bot] in #22518
Update sdk-internal to 0.2.0-main.979 by @bw-ghapp[bot] in #22581🎨 Other
[AI-88] llm: Remove .claude/CONTRIBUTING.md by @SaintPatrck in #22532
New Contributors
@thisisryanswift made their first contribution in #17764
@hammadxcm made their first contribution in #21229Full Changelog: web-v2026.8.0...web-v2026.8.1
Original source - Sep 1, 2026
- Date parsed from source:Sep 1, 2026
- First seen by Releasebot:Sep 2, 2026
Backend API 18.1.7.2
Keeper improves security, notification handling, and audit log reliability with backend fixes, dependency updates, and stronger Automator endpoint hardening.
KA-9494: Updated core security libraries and system dependencies to the latest compliance standards.
KA-9479: Resolved an issue where users received duplicate automated email notifications when access to shared folder records was expiring. Email notification frequency has been corrected to ensure proper notification delivery without repeated alerts.
KA-9480: Fixed timestamp precision handling in backend database queries to prevent processing errors during audit log ingestion. This improves reporting reliability and ensures consistent data storage across system event logs.
KA-9162: Improved hardening of the Automator endpoints based on 3rd party pen testing.
Original source All of your release notes in one feed
Join Releasebot and get updates from Bitwarden and hundreds of other software products.
- Sep 1, 2026
- Date parsed from source:Sep 1, 2026
- First seen by Releasebot:Sep 2, 2026
v0.165.2
Infisical improves admin encryption with a warning before forcing previous root key deactivation.
What's Changed
improvement(admin-encryption): warn before forcing previous root key deactivation by @victorvhs017 in #7912
Full Changelog: v0.165.1...v0.165.2
Original source - Sep 1, 2026
- Date parsed from source:Sep 1, 2026
- First seen by Releasebot:Sep 2, 2026
v0.165.1
Infisical ships PKI, permissions, PAM, and secrets management upgrades, including Windows and Linux PKI sync pre-fetch, folder RBAC, webhook approval events, and a revamped secret replication workflow, while also polishing UI, auth, and certificate handling.
What's Changed
- feat(pki): windows/linux PKI Syns pre-fetch commands by @carlosmonastyrski in #7694
- fix: make approvals check for validation rules by @mathnogueira in #7837
- feat(pki): expose the latest renewal of a certificate so agents can follow renewals by @carlosmonastyrski in #7820
- chore: add upgrade impact for v0.164.1 by @github-actions[bot] in #7840
- docs: fix grammar in dynamic secrets overview by @devin-ai-integration[bot] in #7847
- fix(ui): reset search input when user gets into folder by @adilsitos in #7844
- docs: linux and windows doc improvements by @sheensantoscapadngan in #7846
- improvement: add port number to Splunk provider by @Thiago-AS in #7843
- fix: add blocks for ca incompatibility by @sheensantoscapadngan in #7848
- docs: add AI agent identities to identity counting by @0xArshdeep in #7845
- feat(permissions): folder rbac by @adilsitos in #7762
- fix(kubernetes-auth): pin direct API requests with safeRequest by @victorvhs017 in #7855
- feat(pki-sync): add GCP Certificate Manager Sync by @carlosmonastyrski in #7737
- fix(docs): route vulnerability reports through the disclosure policy by @Vligai in #7856
- fix(auth): pool https agents and fix gateway sni by @victorvhs017 in #7857
- feat(webhooks): approval and change request webhook events by @lobocv in #7780
- docs(wip): top level ia 2 by @adkah in #7830
- docs(secret-rotation): fix typos by @adkah in #7861
- feat(pam): default ssh access to interactive shell by @lb-vn in #7838
- feat(pam): improve error code for deleting discovery cred acc by @lb-vn in #7854
- feat(docs): add folder rbac docs by @adilsitos in #7862
- docs(footer): fix forum link by @adkah in #7865
- fix(certificate): scope certificate private-key read permission to the certificate subject on v3 issuance by @Vligai in #7549
- fix(cert-v3): route DigiCert requests through external issuance on approval by @devin-ai-integration[bot] in #7870
- improvement(approvals): migrate page shell to v3 by @andrewhuhh in #7836
- docs(folder-rbac): enhancements by @adilsitos in #7874
- feat(abac): add trim suffix by @adilsitos in #7817
- improvement(secrets): migrate Vault import dialogs to v3 by @andrewhuhh in #7794
- feat: add kubernetes MI auth template support by @scott-ray-wilson in #7713
- fix: collapse signer approvals into a single setup card until a policy exists by @carlosmonastyrski in #7875
- feat(ui): select all for vault import secret path Combobox by @claude[bot] in #7878
- fix(pam): re-check session validity when privileged access is granted by @lb-vn in #7852
- feat(docs): add ansible folder operations by @adilsitos in #7871
- docs(secrets-mgmt): clarify dual-phase rotation by @adkah in #7864
- docs(secrets-mgmt): refresh spacelift sync by @adkah in #7896
- feat(dynamic-secrets): cut over to shared provider registry by @andrewhuhh in #7839
- fix: pki ux patches by @sheensantoscapadngan in #7853
- feat: set project retention limits by @varonix0 in #7887
- docs(style): add skill for applying docs style by @adkah in #7907
- feat(secret-manager): revamp replicate secrets workflow by @andrewhuhh in #7793
- fix(identity-ldap-auth): stop returning bind password on GET by @victorvhs017 in #7873
- fix(pki): clear NULL extended key usage elements on certificates by @claude[bot] in #7900
- chore(docker): refresh stale libssl pin and slim the runtime image by @Vligai in #7905
- fix: resolved multi line yaml pasting issue by @akhilmhdh in #7920
- chore: storybook preview by @scott-ray-wilson in #7914
- feat: add helper text for digicert profiles during issuance by @sheensantoscapadngan in #7911
- fix(webhook): render the test event for the webhook's type by @lobocv in #7893
- improvement(integrations): move integrations page header and tabs to v3 by @claude[bot] in #7909
- feature(ui): add generic v3 loader component and migrate branded loader call sites by @claude[bot] in #7895
- improvement: refactor cert profile policy creation to be inline by @scott-ray-wilson in #7908
- chore: comment storybook preview links by @andrewhuhh in #7925
- chore(docker): drop the source tree and recommended packages from the image by @Vligai in #7917
- fix(ui): read the real reduced-motion preference in v3 Loader by @claude[bot] in #7927
Full Changelog
v0.164.1...v0.165.1
Original source - Sep 1, 2026
- Date parsed from source:Sep 1, 2026
- First seen by Releasebot:Aug 20, 2026
- Modified by Releasebot:Sep 2, 2026
v2.1.0
Vault ships 2.1.0 with security fixes, major PKI and Agentic Security additions, and broad enterprise and UI improvements. Highlights include Agent Registry UI, automated DNS-01 fulfillment for PKI, PKCS#12 and JKS bundle support, SLH-DSA hybrid signing, plus many bug fixes and stability upgrades.
2.1.0
September 01, 2026
SECURITY
- core: Update go.etcd.io/etcd/client/pkg/v3 to v3.7.1 to fix security vulnerability GO-2026-6107.
- core: Update software.sslmate.com/src/go-pkcs12 to v0.7.2 to fix security vulnerability GO-2026-5052.
CHANGES
- License: Add Agentic IAM terms to client licensing model and update terms for Vault Platform licensing model.
- core: Bump Go version to 1.26.7.
- oauth-resource-server (enterprise): Prevent issuer_id from being mutated after OAuth Resource Server profile creation. Operators must delete and recreate profiles to change the issuer_id.
- oauth-resource-server (enterprise): Prevent unique_id_claim from being mutated after OAuth Resource Server profile creation. Operators must delete and recreate profiles to change the unique_id_claim.
- oauth-resource-server (enterprise): The OAuth Resource Server feature no longer requires activation via the sys/activation-flags/oauth-resource-server/activate endpoint.
- oauth-resource-server (enterprise): Update OAuth Resource Server config to include custom claim options for the token's unique identifier and actor.
- secrets/openldap (enterprise): Update plugin to v0.18.4+ent
FEATURES
- Agent Registry UI (enterprise): Adds a new Agentic Security section to the primary navigation with an Agent Registry page where operators can view, search, and manage registered AI agents, their associated Vault entities and aliases, assigned policies, and operational status.
- Automatic DNS-01 Challenge Fulfillment for PKI External CA: Integrate with the following DNS providers for automatic DNS-01 challenge fulfillment: AWS Route53, Azure DNS, Google Cloud DNS, and BIND and other RFC2136-compliant servers.
- PKI PKCS#12 and JKS Support: Adds support for PKCS#12 (PFX) and Java keytool (JKS) certificate bundles to relevant PKI endpoints. Bundles are returned as base64-encoded, password-protected files.
- SLH-DSA support for Hybrid sign/verify in Transit engine (enterprise): Add support for SLH-DSA as the PQC component for Hybrid sign/verify operations. This is compatible with both ECDSA (p-256, P-384, P-521) and Ed25519.
- secrets/pki-external-ca (enterprise): Add support for handling dns-01 challenges for Azure, AWS, GCP, and rfc2136 DNS.
IMPROVEMENTS
- agent-registry (enterprise): Removed the restriction that disallowed the use of 'deny' in ceiling policies, resulting in request errors.
- agent/pkiexternalca: Replace go.uber.org/atomic with sync/atomic (stdlib) for atomic boolean operations in the pkiexternalca package.
- auth/token: Add global denylist for revoking OAuth JWTs to prevent authorization of specific tokens across all namespaces.
- core/seal (enterprise): Update Oracle Cloud library to enable seal integration with newer regions.
- ui: Bump dompurify from 3.4.6 to 3.4.13.
- ui: Bump shell-quote from 1.8.4 to 1.9.0.
- ui: Exposing the RSA Private Key field in the UI when generating credentials with the snowflake database secrets engine. Previously, this field was only shown in the cli.
- ui: Secrets engine delete confirmation modal now requires typing delete-engine to confirm, displays the engine name, secret count (KV engines only), and a list of what will be permanently deleted. ConfirmModal has now been updated to include a optional type-to-confirm.
BUG FIXES
- agent/pki-external-ca: Fix CA chain extraction from Vault PKI API responses where ca_chain field was always empty in templates due to incorrect type handling of array responses
- api: Account for the HTTP Age header when calculating a lease's remaining lifetime, so that leases read or renewed through a caching proxy such as Vault Agent are renewed before they expire.
- core (enterprise): Fix a data race and potential panic during seal/unseal
- core (enterprise): Fix panic in collectOperatorImportMetrics when router.Route returns a nil response with no error during KVv2 metadata reads on performance secondary nodes. This condition occurs during the WAL-stream partial-sync phase of an initial join.
- core/login: Fix panic on malformed login requests. Vault now returns an error for malformed login payloads instead of dropping the client connection (no data loss).
- core/metrics: Fixed a bug where log_format = "json" had no effect on telemetry sink errors from statsd and statsite backends.
- core/wrapping: sys/wrapping/wrap now enforces uuid-format wrapping tokens, ignoring any caller-requested wrap format.
- core: Fix vault operator migrate -start command when migrating to raft integrated storage.
- core: vault kv put/get now works with external OAuth tokens.
- cubbyhole: Fix cubbyhole writes for JWT tokens in non-root namespaces
- default-auth: Fix issue with legacy default-auth configs that would break as part of upgrading to a newer version of Vault.
- identity: Fixed entity alias creation failing with "mount accessor namespace does not match request namespace" when using a synthetic mount accessor in a namespaced context
- oauth-resource-server (enterprise): Fix issue where optional_authorization_details was incorrectly ignored for delegated (OBO) workflows when the subject has no agent registration, resulting in RAR not being mandatory in those requests.
- plugins: Reading a versioned-only plugin without specifying -version now auto-selects it when only one version exists, or returns an error listing available versions, instead of a silent 404.
- proxy/cache (enterprise): Fixed a bug in the static secret cache where GET requests with ?list=true were incorrectly cached and served stale.
- sdk/rotation: Subsequent calls will no longer allow both the rotation_period and rotation_schedule fields to be set simultaneously. The SDK now explicitly empties the opposing field to guarantee mutual-exclusion.
- secret/pki: Fix ACME order finalize race condition where concurrent requests could double-issue certificates and orphan one from order-keyed tracking
- secret/pki: prevent key rename from accepting a name already held by a different key.
- secrets/database: Sanitize the caller-controlled DisplayName before it is used in generated usernames to prevent SQL injection via username templates. Adds a configuration warning when a username_template references DisplayName without a truncate function.
- secrets/ldap: manually rotating a static role password will restart the rotation TTL once again, matching the behavior prior to v2.0.0
- secrets/nomad: Fix connection exhaustion under high concurrency by introducing a shared, pooled HTTP client with a per-host connection cap. Previously, a new TCP connection was opened for every credential request, causing Nomad to return HTTP 429 "too many concurrent connections" errors when more than 100 leases were generated simultaneously.
- serviceregistration/consul: Fixed an issue where Vault would permanently deregister itself from the Consul service catalog when a SIGHUP/reload signal was sent and the configuration used Consul as the storage backend without an explicit service_registration stanza.
- ui/secrets/pki: Fix issuers list page failing to load when issuer count exceeds 10
- ui: Fix 403 error on auth method Configure page for policies that grant read on sys/auth* but not sys/auth/*.
- ui: Fix Kubernetes auth method not saving token_reviewer_jwt — the wrong OpenAPI schema key (KubernetesConfigureRequest) was used instead of KubernetesConfigureAuthRequest, causing the JWT field to be omitted from the form and API payload on save.
- ui: Fix border clipping on dashboard widget tables by applying overflow-hidden styling.
- ui: Fix open redirect bug in OIDC provider route.
- ui: Fix policy generator flyout rejecting saves when no capabilities are selected for a rule.
- ui: add totalItems property to fix filtered list pagination showing incorrect total page count
- ui: fix spurious "No access" banner when navigating to Vault UI with ?namespace=root in the URL
- Aug 31, 2026
- Date parsed from source:Aug 31, 2026
- First seen by Releasebot:Aug 31, 2026
Aug 31, 2026
Dashlane adds PIN setup for SSO users to use passkeys on sites that require user verification.
If you log in to Dashlane using single sign-on (SSO), you can now set up a PIN to use passkeys on sites that require user verification. More about user verification
If you log in to Dashlane using single sign-on (SSO), you can now set up a PIN to use passkeys on sites that require user verification. More about user verification
Original source - Aug 28, 2026
- Date parsed from source:Aug 28, 2026
- First seen by Releasebot:Aug 28, 2026
- Modified by Releasebot:Aug 31, 2026
Aug 28, 2026
Dashlane fixes a Groupon autofill issue and adds Vault Enforcement to require login before access to critical websites.
Two updates:
- Fixed autofill issue on www.groupon.com where only the first 4 card numbers would autofill
- Admins can now use Vault Enforcement to require users to log in to Dashlane before they access critical websites. Two new articles walk through the setup and the plan member experience.
- Vault Enforcement
- Log in to Dashlane to log in to website
- Aug 28, 2026
- Date parsed from source:Aug 28, 2026
- First seen by Releasebot:May 9, 2026
- Modified by Releasebot:Aug 28, 2026
Aug 28, 2026
Dashlane improves performance with bug fixes and optimizations in this update.
Though not immediately visible, this update includes bug fixes and optimizations for improved performance.
Original source - Aug 27, 2026
- Date parsed from source:Aug 27, 2026
- First seen by Releasebot:Aug 27, 2026
v0.164.1
Infisical adds LDAP, SQL, and Linux validation rules, gateway pool load balancing, and PostgreSQL account discovery, while also improving SSO alias handling, dynamic secret provider forms, and auth email dispatch.
What's Changed
- feat: add validation rules for LDAP, SQL and linux by @mathnogueira in #7568
- docs(cli): add note about --recursive by @adkah in #7832
- chore: add upgrade impact for v0.164.0 by @github-actions[bot] in #7829
- feature(helm): require config.siteUrl in infisical-nkp chart by @0xArshdeep in #7834
- feat(pam): postgres account discovery by @x032205 in #7790
- docs(style): add custom vale ci check by @adkah in #7835
- feat(gateway-pools): load balancing by @bernie-g in #7703
- fix: resolve provisioning identifiers through SSO user aliases by @Thiago-AS in #7827
- feat(dynamic-secrets): migrate identity and access provider forms by @andrewhuhh in #7569
- chore(secrets): remove deprecated IP allowlist frontend by @andrewhuhh in #7799
- feat(dynamic-secrets): migrate data-service and protocol provider forms by @andrewhuhh in #7574
- improvement(auth): harden signup and account recovery email dispatch by @victorvhs017 in #7833
Full Changelog: v0.164.0...v0.164.1
Original source - Aug 26, 2026
- Date parsed from source:Aug 26, 2026
- First seen by Releasebot:Aug 27, 2026
Automator Version 17.1.4
Keeper releases a security-focused Automator update based on third-party penetration testing, urging deployments to upgrade to 17.1.4 and follow recommended ingress requirements so inbound traffic is restricted to Keeper’s infrastructure.
This is a security-focused release based on 3rd party security pen testing. All Automator deployments should be upgraded to version 17.1.4 as soon as possible, or during the next scheduled maintenance window.
As documented, ensure all Automator deployments adhere to our recommended Ingress Requirements, ensuring all inbound traffic is restricted to Keeper's infrastructure.
Security Updates
- KAA-180: Security Updates based on 3rd party vulnerability testing
Important Upgrade Information
Updating to version 17.1.3 from older Automator releases (such as 17.1.0 or 17.1.1) may require a setup and re-initialization step.
For Container Deployments: Update the container image to
17.1.4and restart the service. If upgrading from a previous release containing legacy serialized configuration data, runautomator setup <automator-id>followed byautomator init <automator-id>via Commander as described in the deployment documentation.For Non-Container Deployments: Refer to the Keeper Automator documentation to update service binaries and execute
automator setup/automator initif required.
See the Keeper Automator Documentation for full deployment and configuration management instructions.
Original source