With the release of 2.8.0-beta1, the open-source project KeePassXC has delivered the first major milestone for its upcoming primary release branch. The update thoroughly modernizes the foundation of the open-source password manager, introducing long-awaited features for Linux desktop environments as well as new synchronization options.
Modernization with Qt 6 and Native Wayland Support
The most significant architectural change is the transition of the underlying UI toolkit from Qt 5 to Qt 6. This particularly benefits modern Linux environments: the automatic entry of credentials (Auto-Type) now works natively on Wayland, leveraging the standardized interfaces of XDG Desktop Portals.
Furthermore, the Linux build will henceforth store its application state in the specification-compliant XDG_STATE_HOME directory rather than in the temporary cache directory XDG_CACHE_HOME. In addition to improved AppImage integration, the update resolves a timing issue that occasionally prevented the automatic detection of dark mode during program launch.
New Usability Features and Flexible Data Synchronization
Version 2.8.0 also delivers practical enhancements across all platforms. Quick Unlock can now be configured via Polkit on Linux and via password on macOS. Users also gain fully customizable keyboard shortcuts. For the first time, native binaries are provided for Windows systems running on ARM64.
In terms of data management, the software now supports importing and synchronizing remote databases using external tools. A new database statistics feature breaks down stored passkeys and time-based one-time passwords (TOTP). In addition to standard records, the importer for Proton Pass can now process Wi-Fi credentials, SSH keys, and other data types. Developers and administrators can also generate RSA, ECDSA, and Ed25519 key pairs directly via the integrated SSH agent.
Patched Security Vulnerabilities and Testing Phase
With this new release, the developers have patched multiple vulnerabilities affecting all versions of the 2.7.x branch as well as older releases. The severity levels are classified as low to moderate; according to the project, core cryptographic functions were never compromised. Resolved issues include:
- A use-after-free vulnerability when handling manipulated KDB files (CVE-2026-69150).
- An integer overflow leading to an out-of-bounds read in the legacy KDB importer.
- An entry-reference injection vulnerability via the browser extension.
- Out-of-bounds write operations during encryption via Native Messaging.
- Predictable memory structures when passing SSH keys to Pageant on Windows, which have been replaced with randomized names in shared memory.
Installation packages for version 2.8.0-beta1 are available for Windows, macOS, and Linux via the project’s official GitHub repository. Because this is an early pre-release build, the download is primarily intended for testers. For daily productive use, it is recommended to wait for the final release of version 2.8.0.
Sources: Borncity.com









