Privileged Access Bridge — Changelog¶
Release notes for the Blackfort Privileged Access Bridge (PAB). Newest version first. Versioning follows Semantic Versioning.
Product maturity
PAB combines a newly built, hardened Blackfort portal with a mature session engine. The portal is under active development; these notes describe only features that are actually available.
1.0.2 — 2026-09-15¶
Maintenance release: fixes to recording playback and to the login screen, plus updates to bundled third-party libraries.
Fixed
- Playback of a recorded session now reliably opens the screen recording. For SSH, Telnet and Kubernetes sessions a text transcript could be loaded instead, leaving the picture black. If a session has no screen recording, no playback button is offered any more.
- Playback that cannot start now reports this instead of staying in the loading state indefinitely.
- The login screen stays usable on small displays: where the height is insufficient, the login area scrolls by itself.
- An open consent dialog no longer covers the password field and the login button. Only affects instances that display such a dialog.
Security
Two security advisories for bundled third-party libraries have been picked up. Neither was exploitable in PAB — not over the network and not with valid credentials, because the vulnerable code path is not reached in the way we use these libraries. We updated regardless.
react-router-domto 7.18.2 (GHSA-qwww-vcr4-c8h2). Per the publisher, the advisory only affects applications that use the APIs marked as unstable RSC. The portal is a browser-only application without server-side rendering and does not use them.qsto 6.16.0 (CVE-2026-82417). The advisory requires query parameters to be parsed with theallowPrototypesorplainObjectsoptions and then serialised again. The Backend-for-Frontend parses query parameters with the runtime's simple parser and does not serialise them back.
Maintenance
- Runtime and build base moved to Node 24, bundled third-party libraries brought up to date.
1.0.1 — 2026-07-06¶
- Fixed: the file browser retries automatically and waits longer when the file system is not available yet.
- Fixed: the download button is consistently visible again during sessions.
1.0.0 — 2026-07-01¶
First publicly documented version of the agentless PAM gateway.
Added
- Agentless access through the browser — nothing is installed on the client or the target system.
- Protocol breadth: RDP, SSH, VNC, Telnet and Kubernetes through a single interface.
- Session recording with playback in the portal (recording viewer).
- Real-time supervision: a supervisor can follow live sessions read-only and end them immediately via an emergency stop.
- File transfer into the session through a convenient file browser with folder navigation, multi-select and bulk download; clipboard synchronisation.
- Backend-for-Frontend (BFF) as a security and supervision layer: the session token
stays server-side, the browser only receives an
HttpOnly+Secure+SameSite=Strictcookie (CSRF protection via double-submit token); roles and emergency stop are enforced at the BFF. - Hardened edge: strict Content Security Policy, HSTS, rate limiting and security headers for internet-facing operation.
- Connection and user management in the portal.
- Version display (portal build) in the "System" area.
Security
- Login hardened to use the real client IP (prevents false login lockouts behind a reverse proxy).
- Updated the session playback library to fix a known vulnerability (CVE-2025-59288).