DocumentationAPI ReferenceRelease Notes
Release Notes

U-Series Appliance 4.6.3 release notes

ℹ️

This release applies to U-Series Appliance software version 4.6.3. BeyondTrust recommends upgrading all appliances, including both members of a High Availability pair.

🆕 New features

There are no new features.

✨ Enhancements

Endpoint Privilege Management connectivity is restored automatically after High Availability failover

Endpoint Privilege Management connection passwords are now applied on the new active appliance from the mirrored BeyondInsight database at failover, instead of being transmitted between appliances. Endpoint Privilege Management connectivity recovers automatically after a High Availability failover, with no manual reconfiguration.

ℹ️

For more information, see Configure High Availability.

Clearer permissions messages in the U-Series Appliance web console

The web console now displays clear, component-specific messages when a non-administrator account, for example, an account signed in through SSO, does not have permission to use a feature. Previously these accounts saw a generic error that did not indicate the cause.

🛠️ Issues resolved

Product areaDescriptionResolution
CertificatesCertificate and BeyondInsight encryption-key uploads accepted a caller-supplied destination path.Certificate and encryption-key upload handling is hardened, and uploads are written only to approved appliance locations.
AuthenticationTwo-factor unlock codes could be reused and remained valid for an extended period.Unlock-code validation is strengthened. Codes are now single-use with a shorter validity window, and enabling RDP from removable media requires a BeyondTrust-signed unlock artifact.
AuthenticationAn administrator password change could complete without verifying the current password.Administrator password changes now always verify the current password on the server, and role checks are enforced.
LoggingThe log-snippet endpoint could return files outside the appliance log folders.Log viewer file access is restricted to appliance log folders.
Backup and RestoreBackup restore extracted archives to the root of the C: drive, and backups taken on 4.4.0 and earlier failed to restore.Restore path handling is hardened, and backups taken on 4.4.0 and earlier now restore successfully.
High AvailabilityThe internal database-transport service read and wrote files without authentication.Internal High Availability database-transport file handling is hardened.
High AvailabilityHigh Availability partner endpoints accepted unauthenticated requests that could change database connection settings.High Availability partner endpoints now require API key authentication.
ConfigurationThe SQL management service built statements by interpolating identifiers, and an invalid SQL administrator rename reported success.SQL account management is hardened, and invalid SQL administrator rename attempts are now rejected with a clear error.
Backup and RestoreBackup location and network test endpoints accepted UNC paths without credentials, causing the appliance to authenticate to the target host.Backup network locations without credentials are no longer accepted, and network path test errors are reported more clearly.
RDPA request-supplied trust flag could bypass the two-factor requirement when enabling RDP.Two-factor enforcement for RDP enablement can no longer be bypassed.
NetworkingNetwork and DHCP configuration scripts did not escape adapter alias values before running them.Network configuration command handling is hardened.
ConfigurationSecurity secrets were generated using a seeded pseudo-random source.Generated secrets now use a cryptographically secure random source.
UpdatesUpdates history showed duplicated step details after two environment packages were installed.Updates history now shows the correct step details for each installed package.
APIThe APIAuth header value was concatenated into an internal request URL without validation.API authentication header validation is hardened.
High AvailabilityHigh Availability pairing could hang indefinitely when the partner appliance was unreachable.Partner reset operations are now bounded by explicit timeouts and report the underlying error.

📝 Requirements

  • Upgrade to 4.6.3 from a supported prior U-Series Appliance software version.
  • In a High Availability pair, upgrade both appliances to 4.6.3.
🚧

Important

Enabling RDP from removable media now requires a BeyondTrust-signed unlock artifact. Unlock codes placed directly in command.ini are no longer accepted.

Contact BeyondTrust Technical Support to obtain a signed unlock artifact.

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.