Skip to content

Privileged Access Bridge — Changelog

Release notes for the Blackfort Privileged Access Bridge (PAB). Newest version first. Versioning follows Semantic Versioning.

Product maturity

PAB combines a newly built, hardened Blackfort portal with a mature session engine. The portal is under active development; these notes describe only features that are actually available.

1.0.2 — 2026-09-15

Maintenance release: fixes to recording playback and to the login screen, plus updates to bundled third-party libraries.

Fixed

  • Playback of a recorded session now reliably opens the screen recording. For SSH, Telnet and Kubernetes sessions a text transcript could be loaded instead, leaving the picture black. If a session has no screen recording, no playback button is offered any more.
  • Playback that cannot start now reports this instead of staying in the loading state indefinitely.
  • The login screen stays usable on small displays: where the height is insufficient, the login area scrolls by itself.
  • An open consent dialog no longer covers the password field and the login button. Only affects instances that display such a dialog.

Security

Two security advisories for bundled third-party libraries have been picked up. Neither was exploitable in PAB — not over the network and not with valid credentials, because the vulnerable code path is not reached in the way we use these libraries. We updated regardless.

  • react-router-dom to 7.18.2 (GHSA-qwww-vcr4-c8h2). Per the publisher, the advisory only affects applications that use the APIs marked as unstable RSC. The portal is a browser-only application without server-side rendering and does not use them.
  • qs to 6.16.0 (CVE-2026-82417). The advisory requires query parameters to be parsed with the allowPrototypes or plainObjects options and then serialised again. The Backend-for-Frontend parses query parameters with the runtime's simple parser and does not serialise them back.

Maintenance

  • Runtime and build base moved to Node 24, bundled third-party libraries brought up to date.

1.0.1 — 2026-07-06

  • Fixed: the file browser retries automatically and waits longer when the file system is not available yet.
  • Fixed: the download button is consistently visible again during sessions.

1.0.0 — 2026-07-01

First publicly documented version of the agentless PAM gateway.

Added

  • Agentless access through the browser — nothing is installed on the client or the target system.
  • Protocol breadth: RDP, SSH, VNC, Telnet and Kubernetes through a single interface.
  • Session recording with playback in the portal (recording viewer).
  • Real-time supervision: a supervisor can follow live sessions read-only and end them immediately via an emergency stop.
  • File transfer into the session through a convenient file browser with folder navigation, multi-select and bulk download; clipboard synchronisation.
  • Backend-for-Frontend (BFF) as a security and supervision layer: the session token stays server-side, the browser only receives an HttpOnly+Secure+SameSite=Strict cookie (CSRF protection via double-submit token); roles and emergency stop are enforced at the BFF.
  • Hardened edge: strict Content Security Policy, HSTS, rate limiting and security headers for internet-facing operation.
  • Connection and user management in the portal.
  • Version display (portal build) in the "System" area.

Security

  • Login hardened to use the real client IP (prevents false login lockouts behind a reverse proxy).
  • Updated the session playback library to fix a known vulnerability (CVE-2025-59288).