- Security patches address CVE‑2026‑9793 (JWE request object enforcement), CVE‑2026‑4629 (hard‑coded role mapper injection), CVE‑2026‑14209 (admin UI brute‑force), and two fine‑grained admin permission bypasses (client scope and group chil...
- Bug fixes include WebAuthn authenticator attachment policy bypass, broken clustering CI test, Kustomize role/role‑binding handling, password‑reset commit issue, 500 error on organization scope requests, and Liquibase DB lock provider exc...