Version 2.14.03
This is a patch update to fix user permission matching, External API status codes, and system package permission records.
- Fixed a bug where user permissions did not apply when the Keycloak username did not match the stored permission record (i.e. “Email as username” enabled, renamed accounts, service accounts); permissions now match on the Keycloak user id
- Fixed the External API returning a 400 for all errors; calls now return the correct 401, 403, 404, or 503 status
- Fixed External API checklist, patch scan, tailoring, and POAM uploads reporting success with zero results when the upload was rejected
- Fixed the system package id stored on security group permission records; existing records are repaired automatically on startup
- DISA Template updates as of August 18, 2026 from DISA public.cyber.mil