Automator Version 17.1.2
Released on August 10, 2026
This is a security-focused release addressing several 3rd party penetration testing reports and library depedencies. All Automator deployments should be upgraded to version 17.1.2 as soon as possible, or during the next scheduled maintenance window.
As documented, ensure all Automator deployments adhere to our recommended Ingress Requirements, ensuring all inbound traffic is restricted to Keeper's infrastructure.
Security Updates
KAA-167: Deserialization Hardening Applied a strict ObjectInputFilter allow-list to Java deserialization paths, blocking untrusted classes from being instantiated during object deserialization. Only explicitly permitted packages (Keeper, Protobuf, BouncyCastle, Keycloak, and a minimal set of JDK primitives/collections) are now accepted.
KAA-167: Path Traversal Protection SSL password file path configuration now canonicalizes the resolved path and rejects any path that resolves outside the Automator working directory, preventing directory traversal attacks against local file resources.
3rd party library dependencies: We have upgraded 47 library dependencies in accordance to our regular SDLC process.
Update Instructions
Updating to version 17.1.2 requires a re-initialization due to encryption changes
For container deployments, update the container and restart the service. Then run "automator setup" followed by "automator init" as described in the relevant section "Installation Method" for your type of deployment.
For other deployment methods, see the Automator documentation to update
Advanced Features
See this page for all of the new and advanced features / settings for the Automator service.
Last updated
Was this helpful?

