We’re happy to announce that Domoticz version 2026.4 is now available!
This release puts security first, introduces a whole new icon experience, and brings a long list of improvements for Matter, the Dynamic Dashboard, dzVents and SolarEdge.
https://www.domoticz.com/2026.4/
This release closes a series of access-control issues in the web server, the API and the MCP server. Every JSON API command now has a minimum user level that the web server enforces before the command runs. Among other things:
- The events command is admin only; any logged-in user, including a Viewer, could create an event script that the server executed with the rights of the Domoticz process
- getsettings is admin only, and gethardware no longer returns hardware usernames, passwords and plugin settings to non-admin users
- Two ways to get an unauthenticated request past the login have been closed
- fetchurl (used by the RSS and Calendar widgets) only fetches public internet addresses, so it can no longer be used to read services inside your network
- Sensitive MCP resources and tools are admin only
- Device fields from plugins or a remote master are now SQL-escaped, Blockly strips shell characters from Start Script arguments, and the update scripts validate TLS certificates
Several commands now require higher rights and return HTTP 403 when called with a Viewer (or User) account or token. Now admin only: clearlog, getlog, setplandevicecoords, changeplanorder, dotransferdevice, gettransfers, getshareduserdevices, serial_devices, the Z-Wave and EnOcean node commands, addyeelight, addArilux, events, getsettings and resetsecuritystatus. At least User rights are needed for sendnotification, addlogmessage, emailcamerasnapshot, and the Kodi, Logitech Media Server, HEOS and Panasonic media commands. Please check your scripts and apps (for example external dashboards) after upgrading.
Also note: fetchurl no longer shows an RSS feed or calendar hosted on your own network, and external dashboards such as Dashticz may need an entry in the new 'Allowed CORS Origins' setting under Settings - Security.
- Icon libraries: Font Awesome is built in, and more icon fonts can be added from a URL or by upload (Setup - More Options - Custom Icons); Domoticz serves them locally, and the device icon picker searches every installed library at once
- New 'Icon style' setting: choose 'Classic images' or 'Font Awesome glyphs', plus colour-matched battery glyphs in the devices list
- Security settings: per-application OAuth2 redirect URIs, 'Allowed CORS Origins', and a selectable reverse proxy header (None, X-Forwarded-For, X-Real-IP or Forwarded)
- dzVents: persistent storage is now crash-safe; data is written atomically with an automatic .bak restore, and unchanged data is no longer rewritten (less SD card wear)
- SolarEdge: the web portal works again after SolarEdge retired its old endpoints, now signing in with OAuth2 PKCE; the hardware overview shows the inverter part number and firmware
- Matter: Air Quality, TVOC, Ozone, Formaldehyde, PM1 and Radon sensors, smoke/CO alarms, distinct water leak, rain and freeze detectors, and fixes for contact sensors, blind position and python-matter-server
- Dynamic Dashboard: a House card in the Energy Dashboard, timeout indicators, better touch sliders, and many layout fixes
- Charts: a new Humidity Distribution chart, month and day names in the Domoticz language, and better charts on phones
- Lights: editable percentage values on the RGBW color picker sliders, and touch dragging restored
- Per-user theme settings, and calibration offsets now applied on every device update path
- Updated the bundled DataTables library, clearing three known vulnerabilities
Before updating, please make a FULL backup of your Domoticz folder
(or your SD card if you're running an embedded system).
This ensures you can always roll back to your previous version if needed.
Option 1 – Update via the Web Interface
Setup->Check for Updates->Update
Option 2 – Update via command line
If you are on the previous stable version, run the update command:
Code: Select all
cd domoticz
./updaterelease
Code: Select all
cd domoticz
./updatebeta
You can also rerun the installation script and choose Update:
Code: Select all
sudo bash -c "$(curl -sSfL https://install.domoticz.com)"
A big thank you to all volunteers who contributed to this release — we know it took a lot of effort and dedication!
We highly recommend updating to benefit from the latest fixes and improvements.
— The Domoticz Team