Connect 2026.1 Release Notes
Release Notes Product Versions | |||
|---|---|---|---|
Version | Date | Release | End of Support |
2026.1.1.2 (Connect) 2026.1.1.2 (Loaders) | May 7, 2026 | Major | May 7, 2028 |
2026.1.2.3 (Connect) 2026.1.2.3 (Loaders) | August 19, 2026 | Minor/Patch | May 7, 2028 |
2026.1.3.6 (Connect) 2026.1.3.6 (Connect) | September 30, 2026 | Minor/Patch | May 7, 2028 |
Upgrade Considerations
For best results, we strongly recommend that you download the same version of Server.
New Features
There are currently no new features for this release.
Fixed and Known Issues
Major Release
Version: 2026.1.1.2
There are currently no fixed or known issues for this release.
Patch 3
Version: 2026.1.2.3
Fixed Major Release Version 2026.1.2.3 | |||
|---|---|---|---|
ID | Description | Version | Issue Status |
TCON-7425 | Connect users unable to sign in using Windows authentication and Active Directory Setup in 2025.2, 2026.1. | 2026.1.2.3 | Fixed |
Security Updates
Major Release
Version: 2026.1.1.2
Improved the security of Alteryx Connect by updating several underlying third‑party components to address vulnerabilities identified in internal scans. These updates help ensure Connect continues to run on supported, more secure library versions.
Fixed Major Release Version 2026.1.1.2 | |||
|---|---|---|---|
ID | Description | Version | Issue Status |
TCON-6497 | Upgraded urllib3 python library to 2.6.1 to address BDSA-2025-48097, BDSA-2025-48178, and BDSA-2026-0240. | 2026.1.1.2 | Fixed |
TCON-6524 | Upgraded pycparser python library to 2.21 to address CVE-2022-2255. | 2026.1.1.2 | Fixed |
TCON-6727 | Upgraded PyJMT python library to 2.11.0 to address BDSA-2025-8013. | 2026.1.1.2 | Fixed |
TCON-6951 | Upgraded pyca/cryptography library to 46.0.7 to address BDSA-2026-1856 and BDSA-2026-6691. | 2026.1.1.2 | Fixed |
TCON-6874 | Upgraded these python libraries to address CVE-2024-12797:
| 2026.1.1.2 | Fixed |
Patch 4
Version: 2026.1.3.6
This patch strengthens Connect’s upload validation, image processing, authentication error handling, response security headers, logout and cache behavior, and hostname protection.
Existing Customers Upgrading
A normal upgrade restores the existing Tomcat configuration. This preserves customer ports, SSL, and authentication settings, but it also means the new hostname protection in the packaged server.xml is not automatically applied.
To enable it, stop the Alteryx Connect service and back up C:\Program Files\AlteryxConnect\conf\server.xml (or the equivalent path for a custom installation). Edit the existing file. Do not replace the whole file, as it may contain customer-specific settings:
In the existing
<Engine>opening tag, change onlydefaultHosttoinvalid.invalid:<Engine name="Catalina" defaultHost="invalid.invalid">
Inside that Engine, before the existing
localhostHost, add:<Host name="invalid.invalid" appBase="blocked-webapps" deployOnStartup="false" autoDeploy="false"> <Valve className="org.apache.catalina.valves.ErrorReportValve" showReport="false" showServerInfo="false" /> </Host>Inside the existing
<Host name="localhost" ...>, add an alias for each hostname Tomcat receives and add the error-report Valve if it is not already present:<Alias>connect.example.com</Alias> <Valve className="org.apache.catalina.valves.ErrorReportValve" showReport="false" showServerInfo="false" />Keep all other existing entries inside that Host. Add the alias as a real XML element—not inside a comment. Use only the hostname, not https://, a port, or a path.
Separately, to match the new packaged HTTPS-redirect configuration, add
transportGuaranteeRedirectStatus="308"to the existingLockOutRealmopening tag, retaining its other settings:<Realm className="org.apache.catalina.realm.LockOutRealm" transportGuaranteeRedirectStatus="308">This setting does not, by itself, turn an HTTP-only installation into an HTTPS installation.
Save the file and restart the service. Without steps 1–3, an upgraded installation should continue to operate, but the new Tomcat hostname protection will not be active. Step 4 applies the separate HTTPS-redirect setting included in this patch.
New Customers Installing This Patch
A fresh installation already contains the new Tomcat protection. Before users access Connect through a DNS name, stop the service and add that name inside the localhost Host in C:\Program Files\AlteryxConnect\conf\server.xml:
<Alias>connect.example.com</Alias>
Restart the service. Without the alias, localhost access works, but requests using the unconfigured hostname may return 404. Do not change defaultHost back to localhost.
Reverse-Proxy or Load-Balancer Deployments
Configure an alias for the hostname that the proxy sends to Tomcat. If the proxy replaces the public hostname with an internal one, add the internal hostname as an alias too.
If the immediate proxy connects to Tomcat from a non-local IP address, add that IP to the existing [global] section of C:\Program Files\AlteryxConnect\ac_work\alteryx_connect.properties. For example, if Tomcat sees the proxy as 10.20.30.40:
connect.trusted-proxies=127[.]0[.]0[.]1|::1|0:0:0:0:0:0:0:1|10[.]20[.]30[.]40
Replace 10.20.30.40 with the actual proxy IP; retain the loopback entries. This setting accepts an IP-matching regular expression, not a DNS hostname or an end-user IP. Direct-access installations, or proxies connecting from loopback, need no change. If a non-local proxy is not configured, valid logins can still succeed, but auditing and IP-based login controls may identify multiple users by the shared proxy IP.
Behavior Changes to Expect
New attachment and diagram uploads may be rejected if they exceed the configured limit or have an unsupported, mismatched, or unsafe file type. Existing stored files are not bulk-modified.
Newly saved images are processed to remove metadata. Unusual images may be rejected or appear slightly different.
Failed-login messages disclose less information.
Attachment downloads are no longer intended to remain in the browser cache for one year, so repeated downloads may use more network traffic.
HTTP installations remain supported; the patch does not require a new SSL certificate.
Fixed Minor Release Version 2026.1.3.6 | |||
|---|---|---|---|
ID | Description | Version | Issue Status |
TCON-7708 | Issues while performing WAPT Testing for Alteryx Connect. | 2026.1.3.6 | Fixed |