Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

2026 root-certificate change forces SDK upgrades or apps lose API access

Announced 2025 (effective 1 January 2026)

MediumStatus: OngoingProduct: Dropbox API SDKsYear: 2026

Because some official Dropbox SDKs pinned root certificates, Dropbox's switch to a new certificate root starting 1 January 2026 means apps on the Java, .NET, or Python SDK must upgrade to specific minimum versions or lose access to the API.

What happened

Several official Dropbox SDKs implemented certificate pinning against a built-in list of root certificates. Dropbox announced it would issue its API server certificates from a new root starting on or after 1 January 2026, because the existing root would stop being trusted by many browsers and devices during 2026. Any app pinning the old root would therefore fail to connect after the switch.

To stay connected, developers must upgrade to minimum versions: Java SDK v7.0.0 or later, .NET SDK v7.0.0 or later (if using certificate pinning via DropboxCertHelper.InitializeCertPinning()), and Python SDK v12.0.2 or later. The JavaScript, Objective-C, and Swift SDKs are unaffected, and third-party libraries have to be checked individually. Dropbox urged developers to update 'as soon as possible to ensure continued access,' warning that apps on older affected SDK versions would lose connectivity once the certificate transition occurred.

Impact

This is a hard cutoff: unlike a deprecated feature that degrades gracefully, an app that does not upgrade simply stops reaching the API after the root changes. It places another mandatory-maintenance burden on every team using the affected SDKs — including long-running, lightly maintained backend integrations most at risk of silently breaking — and continues the pattern of Dropbox platform changes that require active developer effort to avoid breakage.

Dropbox's Response / Official Position

Dropbox published a developer-blog post, 'Dropbox API server root certificate changes coming in 2026,' specifying the new root timeline, the affected SDKs and minimum versions, the unaffected SDKs, and a call to upgrade promptly to avoid losing API access.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

In an 8-K filed May 26, 2026, Dropbox disclosed that co-founder Drew Houston would step back as CEO after 19 years, with the Board appointing Ashraf Alkarmi — its General Manager, Core — as Co-Chief Executive Officer effective that date, ahead of Alkarmi becoming sole CEO and Houston moving to executive chairman 'following a transition period.' The handoff arrives as AI upends the software era Dropbox grew up in and the company's revenue sits near flat.

Product Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Dropbox's Q1 and Q2 2026 results both kept total reported revenue growth under 1% year-over-year, the company refinanced debt and repurchased hundreds of millions of dollars in stock over the same six months, and the period closed with a co-CEO handoff, a new product chief, and a routine, tax-related insider stock disposition reported by the Motley Fool.

Pricing & Business PracticesCurrent / Ongoing Issues (2024–2026)
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation