Skip to Content
Release Notes11.5.0 ~ 11.5.8

11.5.0 ~ 11.5.8

QueryPie 11.5.8 Release

August 25, 2026

New Feature

  • [Common] Added Audit log lookup and DAC operations APIs to External API V3 (beta)
  • [DAC] Added IAM authentication support for ElastiCache Connections synchronized through AWS Cloud Provider
  • [SAC] Added Policy-based control over clipboard use for RDP connections
  • [SAC] Added support for configuring session recording in SAC Policy

Improvement

  • [Common] Fixed issue where Authentication Job Change History displayed only the latest entry
  • [Common] Fixed issue where connection information for deleted DB Connections blocked Allowed Zone deletion
  • [Common] Improved connection stability by refreshing Multi Agent Access Tokens before expiration
  • [Common] Improved SAC and DAC connections through Multi Agent to work correctly in environments configured with HTTPS_PROXY
  • [Common] Improved Okta synchronization so existing users’ First Name and Last Name are also updated
  • [DAC] Fixed missing or duplicate requests in SQL Export Request Workflow results from Audit Log Export
  • [DAC] Fixed errors caused by Draft requests being included in SQL Request Workflow Audit Log Export
  • [DAC] Fixed ClickHouse DateTime and DateTime64 results varying by the QueryPie execution environment’s Timezone
  • [DAC] Fixed an engine error when viewing Object Info for a View in ClickHouse Web Editor
  • [DAC] Fixed a WITH ORDINALITY parsing error when DataGrip retrieves PostgreSQL table DDL
  • [DAC] Fixed issue where users removed from a Data Policy Exclude Group continued to be excluded from masking
  • [DAC] Improved DB Connection Accessible Users to show Renewed At, the time permissions were renewed
  • [DAC] Improved Dynamic Proxy so expected connection failures do not repeatedly log Error Stack Traces
  • [DAC] Removed an incorrect Not Implemented message from Excel Export options
  • [DAC] Strengthened External API validation to prevent Policy and Rule registration for DBs that do not support Ledger
  • [DAC] Fixed Data Masking parsing errors when MariaDB Views use the GROUP_CONCAT LIMIT clause
  • [DAC] Fixed handling errors for nested $addFields expressions in MongoDB Aggregate
  • [DAC] Improved permission checks for MongoDB createUser and updateUser commands to work consistently in Web and Proxy
  • [DAC] Improved MongoDB inserts into new Collections to also validate Create permission
  • [DAC] Improved MongoDB Aggregate $out and $merge operations to validate the permissions required to modify data
  • [DAC] Fixed comma-containing column paths not being processed correctly in MongoDB DB Policy Exception Requests
  • [DAC] Fixed ALTER statements being incorrectly treated as SQL Requests when MySQL Ledger Policy is applied
  • [DAC] Improved MySQL connection failures to display the Target DB’s actual error instead of an internal parsing error
  • [DAC] Fixed Web SQL connection failures for mysql_native_password accounts in MySQL Router environments
  • [DAC] Fixed duplicate history entries when filtering Query Audit results
  • [DAC] Fixed errors when running queries against Redshift Datashare Shared Databases
  • [DAC] Added an Import Batch Size setting to Redshift Connections to improve CSV and Excel Import performance
  • [DAC] Improved Trino Proxy so queries are processed correctly when follow-up requests are sent over a new TCP connection
  • [DAC] Expanded blocking of unconditional changes and deletions to MongoDB, DocumentDB, and DynamoDB in Web SQL Editor and MongoDB and DocumentDB in Proxy
  • [DAC] Improved performance by skipping unnecessary DML analysis when full scan warnings and unconditional query blocking are disabled
  • [DAC] Improved the Workflow Assignee dropdown so it remains open while selecting multiple assignees
  • [SAC] Fixed Azure Cloud Provider synchronization Jobs remaining in Running state when API responses are delayed
  • [KAC] Fixed AWS icons being displayed for Clusters synchronized through GCP Cloud Provider
  • [KAC] Improved validation to identify a missing Scheme in a Cluster API URL before registration
  • [KAC] Fixed a declaredFeatures parsing error when viewing Node summaries for Kubernetes 1.36.1 Clusters
  • [KAC] Fixed missing default and Wide output columns in kubectl lookups through KAC Proxy
  • [KAC] Fixed deleted users remaining in the Users / Groups list for Roles

QueryPie 11.5.7 Release

July 2, 2026

New Feature

  • [Common] Added display of licensed user count and users who accessed in the last 30 days within the license scope
  • [DAC] Added Result Reuse option for Athena Connections
  • [DAC] Added ability to block SQL execution without WHERE clauses in SQL Editor and RDB targets
  • [DAC] Added support for collecting Label information during GCP Cloud SQL synchronization and using it as Cloud Provider filter tags
  • [KAC] Added GCP Cloud Provider Tag-based synchronization
  • [KAC] Added YAML editing, local validation, and change Diff Review features in Web Client

Improvement

  • [Common] Fixed a vulnerability where remaining SQLJob token-related code removed in 10.2.6 could be used in External API
  • [Common] Added attachments with expiring target details to SAC/DAC permission expiration notification emails
  • [Common] Added force option support to User Profile lookup and update External APIs
  • [Common] Improved API Token Allowed Zone changes to be refreshed immediately
  • [Common] Improved Vault AppRole Namespace application error handling
  • [Common] Fixed User Not Found error when viewing Job execution history for deleted users
  • [Common] Improved Multi Agent token handling security
  • [Common] Improved client JavaScript bundle so unnecessary internal IP information is not included
  • [DAC] Added PostgreSQL RETURNING statement support for data masking policies
  • [DAC] Improved Draft Workflow entry to show an error message when referencing a Connection without access permission
  • [DAC] Fixed intermittent JavaScript errors during DAC Audit filtering
  • [DAC] Fixed multiple query handling errors in Workflow SQL Export Requests
  • [DAC] Improved Privilege Type editing so Privilege Name can also be changed
  • [DAC] Fixed issue where an incorrect Proxy port error popup was shown when accessing MongoDB
  • [DAC] Fixed Athena CREATE PROTECTED MULTI DIALECT VIEW parsing error
  • [DAC] Improved DB Policy Exception Request Approval Permission so it is exposed in the Roles Policy list
  • [DAC] Improved Trino Proxy connections so query cancel requests are applied correctly
  • [DAC] Improved Trino / Presto Proxy parse errors so they are delivered as proper failure responses
  • [DAC] Fixed issue where workflows were incorrectly shown as failed due to parsing delay while processing MongoDB SQL Requests
  • [DAC] Fixed status display issue where failed query execution appeared successful in QueryPie Web
  • [DAC] Fixed partition key column insert error in Impala
  • [DAC] Improved Redis Cluster read/write routing stability during SQL Request processing
  • [DAC] Fixed issue where unmasked fields were displayed as null in MongoDB Aggregate queries
  • [SAC] Improved the Add Account screen to query only required settings without unnecessary full configuration permissions
  • [SAC] Improved Windows Server Agent remote upgrades so they are not treated as failed in slow network environments
  • [SAC] Improved TACACS authentication processing logic
  • [SAC] Improved RDP session handling so domain controller network errors during session creation do not interrupt session processing
  • [KAC] Improved GCP Cloud Provider API and scheduled synchronization to work correctly
  • [KAC] Fixed WEB ACL blocking issue by preserving the actual client IP in Kubernetes Web Client requests
  • [KAC] Improved Kubernetes Web Client internal proxy communication path to fix connection issues in NLB environments
  • [KAC] Improved Kubernetes Web Client status display, error handling, and operational UX
  • [KAC] Fixed User Not Found error when deleting Role Assignment after deleting a user

QueryPie 11.5.6 Release

May 29, 2026

New Feature

  • [Common] Expanded support for the SCIM 2.0 standard protocol, including PATCH and externalId support and reactivation of inactive users
  • [Common] Added External API V3 (beta) User APIs for creating, retrieving, updating, and deleting users; activating and deactivating users; resetting passwords; managing profiles, groups, and Allowed Zones; retrieving authentication settings; and synchronizing IdPs
  • [DAC] Added Vault-based Secret Store integration support for GCP Cloud Providers
  • [DAC] Added Secret Store integration support for BigQuery and Google Spanner Connections
  • [DAC] Added Secret Store Auth Type support when configuring a DB Jumphost (SSH Tunnel)
  • [DAC] Added RTA connection support for AWS DocumentDB Clusters
  • [SAC] Added authentication and Role change features in CLI
  • [SAC] Added Secret Store (Vault SSH CA) Auth Type for Jumphost server authentication
  • [KAC] Added External APIs for retrieving, creating, updating, and deleting K8s Cloud Providers

Improvement

  • [Common] Improved configuration so User Agent download items can be hidden through environment variables
  • [Common] Fixed Audit Log Export creation errors
  • [Common] Improved Workflow submission so approvals can be separated by Connection Owner
  • [Common] Improved attribute-based Workflow approval rules and assignment methods
  • [Common] Added an option to disable Multi Agent GPU acceleration
  • [Common] Fixed issues related to password reuse for newly created users
  • [Common] Improved permission expiration notification emails to include environment information and details about expiring permissions
  • [DAC] Added the AWS ap-southeast-7 (Thailand) region to Cloud Provider synchronization regions
  • [DAC] Added Redis Username-based authentication support for reverse tunnels
  • [DAC] Improved tunnel list sync speed after Headless Agent tunnel refresh
  • [DAC] Improved usability for UserName filtering and lookup on the DB Access Control Admin page
  • [DAC] Improved warning text and visibility for Auto Commit Off status
  • [DAC] Fixed schema-based access control permission check errors when using MySQL JSON_TABLE
  • [DAC] Fixed ClickHouse/Trino/Athena HTTP proxy connection failures when Proxy Protocol v2 is enabled on AWS NLB
  • [DAC] Improved BigQuery Connection settings synchronized with a Cloud Provider SA Key so the Service Account can be modified and retained
  • [DAC] Fixed issue where Proxy settings were automatically disabled in Redis Cluster mode for ElastiCache/Valkey, with a warning message displayed
  • [DAC] Fixed Athena autocomplete data creation issue
  • [DAC] Fixed Lost Connection issues when running large queries
  • [DAC] Fixed intermittent SQL Server connection issues after upgrading to 11.4.3
  • [SAC] Added Seamless SSH support in Headless Agent
  • [SAC] Added MFA (OTP) authentication support for Internal DB in Headless Agent
  • [SAC] Improved Cloud Provider Auto Configuration so SSH Port and Tag can be edited
  • [SAC] Improved detailed lookup performance by tuning the server_policy_versions lookup query
  • [SAC] Improved security of command blocking messages
  • [SAC] Fixed issue where RDP sessions were blocked when manually entered account passwords needed to be changed
  • [KAC] Added Auto Configuration Upon Synchronization (Tag) support during initial K8s Cloud Provider synchronization

QueryPie 11.5.5 Release

April 21, 2026

New Feature

  • [DAC] Added permission control for Audit Log viewing
  • [DAC] Added ClickHouse HTTPS connection support
  • [DAC] Added Cubrid support (policy application and Proxy not supported).
  • [SAC] Added support for viewing Server Policy details and an API for retrieving a single policy
  • [KAC] Added KAC Web Client (beta)

Improvement

  • [Common] Improved attribute-based Workflow approval processing
  • [Common] Improved email display in approval documents to distinguish approvers with the same name
  • [Common] Improved exception handling for Approval Expiration Job
  • [Common] Improved password change flow for users with expired passwords in Admin Page Access Control environments
  • [Common] Improved error messages when duplicate permissions are held during SQL Request processing
  • [DAC] Improved display of deleted Connection information in Workflow approval history
  • [DAC] Addressed DB Access History query errors and improved stability
  • [DAC] Improved table name display when creating SQL Export Requests
  • [DAC] Added an option to disable Start On Approval
  • [DAC] Applied utf8mb4 charset to the DML Snapshot DB for new installations
  • [DAC] Improved MongoDB insertMany parsing errors
  • [DAC] Fixed SHOW CREATE VIEW permission error when querying Impala VIEWs
  • [DAC] Improved SSH Tunneling connection stability
  • [DAC] Fixed issue where DML Snapshot could be turned OFF on connections with Ledger policies
  • [DAC] Fixed External API SQL Request call error when using forced DML approval
  • [DAC] Fixed expired password change error for MySQL host-specific accounts
  • [DAC] Improved issue where DocumentDB Reader endpoints were routed to Writer instances
  • [SAC] Improved UI display at the bottom of the left server list in Web Editor
  • [SAC] Improved keyboard-interactive access
  • [SAC] Improved stability of new session creation by fixing the cause of port exhaustion in the reverse tunnel agent

QueryPie 11.5.4 Release

March 20, 2026

New Feature

  • [DAC] Workflow SQL Execution Request Draft save/view/edit/submit functionality and External API support
  • [DAC] SAP HANA Web Editor Auto Commit ON/OFF feature support
  • [DAC] SAP HANA procedure/function block syntax support
  • [DAC] Added Trino UNNEST syntax support
  • [DAC] Added Trino datasource Kerberos authentication support
  • [KAC] Added Vault Secret Store integration for GCP Cloud Provider and GKE Connection

Improvement

  • [Common] Fixed issue where agent terminated during Google Workspace SAML login on Multi Agent (macOS)
  • [Common] Fixed issue where session disconnected when pressing arrow keys in SSH shell
  • [DAC] Fixed impersonation error due to unhandled X-Trino-Original-User header in Trino JDBC 426+ environment
  • [DAC] Fixed intermittent “The request is already executed” / Aborted error in Legacy policy-based SQL Request Workflow
  • [DAC] Fixed issue where unmasking permission was not properly applied when exporting JOIN/Expression columns
  • [DAC] Fixed startup failure due to unnecessary HTTPS certificate loading in Impala TCP binary mode
  • [DAC] Fixed issue where same session became unresponsive after Syntax error occurred in Vertica
  • [DAC] Improved metadata query executed during Trino proxy connection
  • [DAC] Fixed missing CREATE statement permission verification in Trino schema access control
  • [DAC] Improved minWritableBytes error when querying SAP HANA BLOB type
  • [DAC] Fixed IndexOutOfBoundsException occurring during Cloud Provider synchronization
  • [DAC] Fixed issue where session was interrupted or failed during large file processing when executing MySQL LOAD DATA LOCAL INFILE
  • [DAC/SAC] Fixed issue where Port Forwarding was not properly maintained when using NOVA Reverse Tunnel, causing remote DB connection failure
  • [SAC] Fixed code signing certificate compatibility issue during Windows Server Agent remote update
  • [SAC] Improved kubectl command exception handling

QueryPie 11.5.3 Release

February 27, 2026

Improvement

  • [Common] Fixed issue where emails continued to be sent even after disabling Workflow notifications in Email Integration
  • [Common] Fixed sync failure issue due to resource path case mismatch during Azure VM Cloud Provider synchronization
  • [DAC/SAC] Fixed zombie session accumulation and port exhaustion issue due to missing keepalive in Reverse Tunnel
  • [DAC] Fixed issue where Redis Cluster connection via Reverse Tunnel was not possible
  • [DAC] Fixed Impala connection failure issue via Agent Proxy

QueryPie 11.5.2 Release

February 11, 2026

Improvement

  • [SAC] Added locked file handling logic when upgrading Server Agent 10.2.x legacy
  • [SAC] Fixed Server Agent auto-update signature verification logic
  • [SAC] Fixed Server Agent code signing verification logic

QueryPie 11.5.1 Release

January 22, 2026

New Feature

  • [Common] License MCP Feature added
  • [DAC] Added Select Audit Snapshot feature to save complete SELECT query results to S3 (Advanced only)
  • [DAC] Implemented schema-based access control Workflow Audit Log Export
  • [DAC] Added Stateful Session management feature for MCP
  • [DAC] Added Spanner Batch DML request processing support
  • [SAC] Added IP selection feature to RDP Server Agent Host column
  • [SAC] Added feature to save complete list of Server Agent unicast addresses to DB

Improvement

  • [Common] Added /userinfo API for Access Token expiration time inquiry
  • [Common] Applied mandatory authentication to GetEnvironment, GetKacProxyEnvironment API
  • [Common] Fixed error when designating a substitute approver
  • [Common] Addressed System.Text.Json (CVE-2024-30105) and System.Text.Encodings.Web (CVE-2021-26701) vulnerabilities
  • [DAC] Added searchFilters option to CloudProvider External API
  • [DAC] Improved to record tables inside subqueries in Query Audit
  • [DAC] Improved JDBC Connection Dispose stability and added Connection status check
  • [DAC] Improved JDBC Connection Dispose stability to resolve APP server memory overload issue and added ExecutionPipeline Connection null check
  • [DAC] Added force termination and Connection status check when stopping Redshift
  • [DAC] Fixed issue occurring when using export request with query using WITH clause in Impala via Workflow
  • [DAC] Fixed ClickHouse proxy connection error
  • [DAC] Fixed issue where tags were not displayed in DB Policy Exception
  • [DAC] Improved Privilege type column header to be sortable by click in DB Access Request in Workflow
  • [SAC] Fixed Windows Server Remote Desktop connection termination due to RDP session time overflow
  • [SAC] Added Headless Agent automatic re-authentication support
  • [SAC] Improved Server Agent behavior to resolve MCCS redundancy Windows Server communication failure issue

QueryPie 11.5.0 Release

December 15, 2025

New Feature

  • [Common] Email notification functionality for privilege expiration (Deactivated) added
  • [Common] Logging functionality for access attempts from unauthorized IPs added
  • [DAC] Google Spanner policy and Proxy support
  • [DAC] ClickHouse policy and Proxy support
  • [DAC] Vertica Proxy support
  • [DAC] Schema access control implementation and approval request integration

Improvement

  • [Common] Display Name display improvement when using SAML authentication
  • [Common] MFA application improvement for Identity Provider
  • [Common] Admin Role - Database Access Control Read-only permission added
  • [Common] DB Access Request Connection Owner selection improvement in Workflow Approval Rule
  • [Common] Invalid license handling improvement
  • [Common] API Docs required field display improvement
  • [Common] Fixed issue where Multi Agent retried connection with expired token
  • [Common] Current IP address display on IP access restriction screen
  • [Common] Fixed Lock wait timeout error when attempting login during Dry run in IdP settings
  • [DAC] Execution Status improvement when approver rejects SQL Request, SQL Export Request
  • [DAC] Exception Management workflow privilege detail status management improvement
  • [DAC] Table name display improvement in Web Editor Import popup window
  • [DAC] Query Audit Label display fix when querying MongoDB Ledger Table
  • [DAC] Display method fix when executor cancels in Urgent mode in Workflow
  • [DAC] Error handling improvement when MySQL connection has no account information (Id/Password)
  • [DAC] Column information update improvement when changing sheets in Excel Import
  • [DAC] Max Display Rows setting behavior improvement
  • [DAC] Handling improvement when MongoDB masking target field is Array
  • [DAC] PostgreSQL Prepare Statement Integer Null Parameter handling improvement
  • [DAC] Proxy Usage validation strengthening when Redis Cluster is enabled
  • [DAC] Modified to allow multiple tag selection in DB Policy Exception Request
  • [DAC] Fixed issue where JDBC.NET Process did not terminate when Engine abnormally terminated
  • [DAC] Fixed error occurrence issue when importing PostgreSQL/Redshift
  • [DAC] Private certificate support when connecting Trino with TLS
  • [DAC] Excluded expired users from Connection Accessible Users list
  • [DAC] Improvement to allow reusing previous reason when entering reason in Web Editor
  • [DAC] MongoDB / DocumentDB Data Tab page size limited to 100
  • [DAC] Fixed issue where Ledger was not recorded in Query Audit when executing Ledger Workflow
  • [DAC] Password change UI support when Vertica password expires
  • [DAC] Fixed issue where table alias was not properly analyzed in DELETE FROM table statement
  • [SAC] Prohibited command behavior improvement - history edit case handling
  • [SAC] Session Monitoring menu location change and Server Monitoring Full Access permission added
Last updated on