Want the full details? Click the link below!
Release 26.09.0 overview
NPS-D 26.09.0 is a bridge and security release. It makes MongoDB 8.0 the standard database backend for new installations and provides the tools required to migrate existing single-node and three-node deployments from MongoDB 4.0 to MongoDB 8.0. It also updates third-party components to address known security issues.
Action required for MongoDB 4.0 deployments: MongoDB 4.0 will not be supported after NPS-D 26.09.0. NPS-D 26.09.1 and all later releases will support MongoDB 8.0 only. Customers still using MongoDB 4.0 must deploy 26.09.0 and complete the database migration before upgrading to 26.09.1 or any later release.
For the complete procedure, see Upgrade MongoDB 4.0 to 8.0 for NPS-D.
Release path
- 26.09.0, bridge release: Adds the supported MongoDB 4.0 to 8.0 migration path while keeping the current NPS-D backend runtime.
- 26.09.1, planned for early October 2026: Upgrades the backend to Python 3.13 and current supported libraries and includes additional security fixes. This release requires MongoDB 8.0; MongoDB 4.0 is no longer supported.
Recommended installation method
For new NPS-D installations, Netwrix recommends the container-based deployment method. It supports single-node and three-node high-availability cluster deployments and provides prerequisites, deployment steps, and verification guidance.
Bug Fixes
| ID | Description |
|---|---|
| 440371 | Updated web assets now load after an upgrade. Versioned CSS, JavaScript, and icon files prevent older browser-cached files from hiding interface changes. |
| PSC-1823 | The API service Stop control now explains why it is unavailable. The Services page shows a disabled control with a reason instead of an empty table cell. |
MongoDB 4.0 to 8.0
NPS-D 26.09.0 introduces MongoDB 8.0 as the standard database backend for new installations and provides a guided migration path for existing MongoDB 4.0 deployments. The process supports both single-node installations and three-node replica-set clusters.
Moving to MongoDB 8.0 brings the NPS-D database platform to a supported technology baseline. This supports ongoing security maintenance, enables future releases to adopt current backend runtimes and libraries, and creates a foundation for continued improvements in performance, reliability, and product capabilities.
| ID | Description |
|---|---|
| 445483 | Database compatibility for the bridge release. NPS-D 26.09.0 supports both MongoDB 4.0 and MongoDB 8.0 while customers complete the migration. |
| 445924, 445932, 445933, 445934 | Guided migration tooling for single-node deployments. Readiness checks, data copy, progress reporting, validation, and final cutover provide the supported path to MongoDB 8.0. |
| 447426, 447427, 447428, 447429, 447430, 447431 | Guided migration tooling for three-node clusters. The process creates a parallel MongoDB 8.0 replica set, copies and reconciles data, validates the result, and completes the database switch. |
| 447584, 452125, 452444, 452802 | Migration reliability and performance for large databases. The cutover process confirms that database writes have stopped, uses optimized comparison paths for large datasets, and records stage timing for clearer progress monitoring. |
| 452140, 452141, 452433 | Migration recovery and database switching. Data copy operations can be resumed safely, and additional checks help prevent incomplete service switches or stale MongoDB 4.0 references. |
| 445850, 445851, 445853, 445922, 447432 | MongoDB 8.0 for new deployments. New single-node and three-node installations use MongoDB 8.0 by default, with setup validation and clear deployment status. |
| 445852 | Database image selection. The deployment pull command uses the configured MongoDB version instead of a fixed MongoDB 4.0 reference. |
| 446095 | Database administration throughout migration. The s1 db, s1 set-password, and s1 database-status commands follow the active database before, during, and after migration. |
| 447213 | Live database version reporting. NPS-D reads the running MongoDB engine version instead of relying on the container image label. |
Other Improvements
| ID | Description |
|---|---|
| 445998 | Added optional automatic redirection to SAML sign-in. Administrators can enable Auto-Redirect to IdP in SAML settings. The option is disabled by default. |
| 448613, PSC-1824 | Updated customer-facing product names. The dashboard, sign-in, browser error, and domain access information screens now use current NPS-D and Netwrix naming. |
| 440629 | Sorted Access Risk domains alphabetically. Domain selectors on Access Risk pages are now easier to scan. |
Security
| ID | Description |
|---|---|
| 444803, 444972, 445497, 447760, 447798, 449316 | Updated third-party components. This release updates supported NPS-D components and tooling to address known security issues and improve dependency maintenance. |
Need help with this update?
There are many different ways to get help with our products!
| Situation | Action |
|---|---|
| If you feel the product is broken and not working as intended… | Contact Support |
| If you have a question you’d like to ask other experts… | Create a discussion in the community: Privilege Secure > Discussions & Questions |
| If you have a feature request… | Let our product team know directly: Privilege Secure > Ideas |
| If you have something cool to show… | Show everyone what you built: Privilege Secure > Show & Tell |
What are your thoughts?
We are always happy to hear from our users on what you like, and what you hope to see in the future. Please, share your thoughts below!
