Sandbox Wallix

Search

rtaImage.jpg

Welcome to WALLIX Customer Support Portal
You can also reach us on:
📞 +33.1.70.36.37.50 (Europe)  ðŸ“ž+1 438.814.0255 (Americas)

Categories

WALLIX Bastion 12.4.1 — Important update on how we count Named Users

Hi everyone,

We are rolling out an important update to WALLIX Bastion licensing, available from version 12.4.1.

What's changing — and what's not

The licensing model itself does NOT change. What changes is the way we count Named Users: Bastion now uses a more accurate, usage-driven method to measure your actual consumption.

Please note: this update concerns Named Users on WALLIX Bastion only — not WALLIX Access Manager.

What this means for you

From version 12.4.1, you will be able to monitor your Named Users consumption directly in Bastion's license page, which provides a centralised view of your usage vs. your contract limits.

This is designed to help you:

  • Better understand your actual usage,
  • Anticipate any adjustments before they become necessary,
  • Optimise your licensing in line with your real needs.

What to expect next

Enforcement — meaning new users being blocked when the limit is reached — will be activated in a future Bastion version, after prior notice. No action is required from your side at this stage.

If you have any questions, our Support team is available via the Support Portal or through your usual WALLIX contact.

Best regards,
WALLIX Customer Success

WALLIX Security Advisory - Bastion & Access Manager

Security Advisory - WALLIX Bastion (Critical)

WSA-2026-07-0001: Unauthenticated privilege escalation via the REST API (CVSS 10.0). All affected customers are urged to apply the fix as soon as possible.

Affected & Fixed Versions

  • Affected versions: 12.3.0 to 12.3.6, and 12.4.0
  • Fixed versions: 12.4.1 or higher
  • Not affected: 12.0.x and all versions prior to 12.3.0
For more information, please visit: https://www.wallix.com/support-services/alerts/

Security Advisory - WALLIX Access Manager (High)

WSA-2026-07-0002: Unauthenticated authentication bypass in the SAML Service Provider (CVSS 8.7). All affected customers are urged to apply the fix as soon as possible.

Affected & Fixed Versions

  • Affected versions: all instances with a SAML federation configured (up to and including 5.1.9, 5.2.6 and 6.0.3)
  • Fixed versions: 5.1.10, 5.2.7, 6.0.4 or higher
  • Not affected: instances with no SAML federation configured

SaaS Environments

  • The W1RA SaaS environments are already up to date.
  • The W1PAM SaaS environments are currently being updated by WALLIX, in coordination with our customers.

More Information

A Knowledge Base article detailing the Access Manager vulnerability (indicators of compromise and log-review guidance) is available here: Access Manager Security Advisory - Knowledge Base

For assistance with the mitigation steps, please open a ticket on the support portal.

Latest versions

Product Version Release date Status
Bastion 12.4.0 25/06/2026 Controlled Release, available upon request
Bastion 12.3.6 02/06/2026 Generally Available
Bastion 12.0.23 22/05/2026 Generally Available
Access Manager 6.0.3 22/05/2026 Generally Available
Access Manager 5.2.6 12/05/2026 Generally Available
Access Manager 5.1.9 01/07/2026 Controlled Release, available upon request
Access Manager 5.1.8 11/05/2026 Generally Available
WALLIX PEDM 5.4 18/12/2024 Generally Available

WALLIX Products versioning and releases

Please find information about our versioning and end-of-life policies through the following link:
WALLIX Products versioning and releases