Release v3.14.14 (2026-09-09)

Last updated: September 9, 2026

Update Notes

Some changes may require action before updating to this version. Visit the Guidance on Updating section before beginning the update process.

**NOTE: **A fix from a 3.14.8 contains an important update that resolves conflict behavior with IAM policies in the Kion database. As with all upgrades, we recommend that you ensure that you have a current, manual database snapshot before upgrading your system.

What's New

  • Creating, editing, or deleting a Cloud Access Role on a project is now treated as high priority in the queue resulting in near real-time syncs to AWS IAM.

Bug Fixes

  • (14126) Fixed an issue where debug-level logging could record plaintext AWS credentials when the IAM service client was created.
  • (14029) Fixed an issue by hardening an internal registration endpoint for the application. Because of this change, the Cloud Administrators feature will not update in this release. Customers who require this functionality in their environment should reach out to Kion Support for assistance in restoring this capability.
  • (13911) Fixed an issue that could allow unauthorized access to Funding Source data when searching within an OU.
  • (13888) Fixed an issue that caused Azure tenant credentials to be stored in plaintext when updating a billing source. After upgrading, we recommend that you rotate your Azure Secret using these instructions.
  • (13707): Fixed an issue that showed deleted resources as active in Resource Inventory when the resource was the last one deleted.
  • (13581): Fixed an issue that incorrectly added the Manage AWS Service Control Policies permission to the Read-Only/Auditor role. This has been updated to point to the correct Browse AWS Service Control Policies permission.
  • (13569): Fixed an issue preventing the azure.subscription resource from being usable in Cloud Custodian Compliance Checks when operating against Azure Government environments.
  • (13469): Fixed an issue after recreating an IAM role with the same name as a deleted role which can inadvertently remove that role from AWS.
  • (13438) Fixed an issue that caused Kion to remove IAM policies from managed accounts when those policies were not created by Kion
  • (11971): Fixed and issue that prevented users with the Global Manage AWS AMI permission from updating and deleting AWS AMIs.
  • (13783, 14067, 13995, 13925, 14068): Updated dependencies to resolve vulnerabilities.

Update Files

Different types of deployments require different update files. For information on which files you need for your deployment type, see Updating Kion.

Downloads