Skip to content

v6.27.4

Choose a tag to compare

@bruntib bruntib released this 23 Apr 09:20

This is a security release that fixes a critical authorization issue. Please, upgrade your servers as soon as possible.
Corresponding CVE ID: CVE-2026-25660

Thanks for @mtolley for reporting this issue.

  • Add missing VIEW permission check 7d60d1e
  • Additional logic for handling missing auth sessions 75b3913
  • Relax permissions requirements for task management fd9f405
  • [fix] Fix invisible chars in error plist (#4809)

Full Changelog: v6.27.3...v6.27.4