9.10.3 (2026-10-05)
Bug Fixes
- Session creation endpoint bypasses create and addField class-level permissions (GHSA-gj37-5hg5-p729) (#10744) (ef08e80)
- User update accepts an empty username or password (#10752) (99444cf)
- User update runs checks against the target account before authorization (GHSA-p49q-9w65-f9p7) (#10746) (643b918)