Released: 29 September 2026
New features, enhancements, bug fixes, and security fixes in Postgres Enterprise Manager 10.6.0 include the following:
Highlights
- Support for RHEL 10 and Debian 13
- New Job Templates to create reusable job definitions
- Improved self-monitoring capabilities via the new Probe Diagnostics feature
- Monitor log errors and autovacuum with new built-in probes and alerts
Enhancements
| Description |
|---|
Introduced Job Templates for agent-agnostic, reusable job definitions that can fan out to multiple targets.Job Templates let a single job definition run across many agents instead of requiring a separate job per target. Import and export of Job Templates is also supported. |
| Added the Probe Diagnostics UI for per-probe health and performance investigation. |
Introduced end-to-end password-in-transit encryption.Browser-to-server credentials are now encrypted with RSA-OAEP: the server generates per-session RSA keypairs and the client uses the Web Crypto API, with un-decryptable ciphertext rejected as a bad request. Feature-gated via |
Added threshold-aware autovacuum and autoanalyze overdue alerts.Both alerts now consider per-table size rather than raw time-since-last-run, so noisy small tables no longer generate false positives while large tables with a genuine backlog surface promptly. |
Added the |
Added |
Added the ability to email scheduled reports over SMTP.Scheduled reports can now be sent as HTML or JSON file attachments over SMTP, with the report rendered entirely in the database. |
Added Kerberos service-ticket authentication mode.The PEM web tier can now maintain a single shared credential cache from a service keytab and connect to the PEM backend as a service principal, while PostgreSQL maps the SPN to a database role via |
Added monitoring support for PostgreSQL 19 and EPAS 19.The probe and alert template surface has been updated to cover the new server version. |
Added support for custom, user-managed encryption keys for Agent Server Binding (ASB) passwords.Encryption keys can now be supplied via |
Added a recurring system job to purge data belonging to deleted agents, servers, and Barman tools.The "Purge deleted objects" job runs every 15 minutes and re-evaluates the |
Added support for Debian 13 (Trixie) as a customer runtime platform.New runtime requirements files ship for |
| Bundled HTTPD 2.4.68 with the PEM installer for Windows. |
| Added support for RHEL 10 on arm64, ppc64le, and s390x platforms. |
| Enhanced the agent watchdog subsystem for improved process resilience and observability. |
Added threshold ordering validation to the Profile PUT API.The endpoint now rejects mis-ordered thresholds (ascending required for the |
| Improved the performance of the Grid View in dialogues. |
| Duplicate webhook name validation now runs on Add rather than only on Save, so the user is warned earlier in the flow. |
Custom probes can now carry a user-specified internal name.The create dialog adds an "Internal name" field that auto-populates as |
Users holding the Scheduled Tasks role can now see and manage jobs on their own agents.System jobs remain admin-only, and schedule exceptions (skip dates) are covered by the same scope. |
| Added a portable way to check whether IPv6 is enabled. |
Added indexes on |
Security Fixes
| Description |
|---|
Fixed CVE-2026-86861, a symlink time-of-check-to-time-of-use (TOCTOU) vulnerability in the File Manager.Closed a race window in |
Fixed CVE-2026-86864, a vulnerability whereby the backup database was not passed via PGDATABASE. |
Fixed CVE-2026-86862, a vulnerability whereby the restore/maintenance database was not passed via PGDATABASE. |
Changes
| Description | Addresses |
|---|---|
Hardcoded both the agent heartbeat and server heartbeat intervals to 15 seconds for consistency.This removes the previous mismatch where the two intervals could drift apart under configuration overrides. You can still configure the heartbeat tolerance as in previous versions, but this now affect only the tolerance and not the underlying heartbeat intervals. | |
Removed the 24-hour cap on scheduled alert blackout duration.The REST API v17 endpoint now accepts any positive integer number of hours; the legacy endpoint still accepts the "N hour(s)" string form; and the UI field validates a minimum of 1. Operators can now schedule multi-day maintenance windows in a single blackout. | 62855 |
Hardened the Content Security Policy with per-request nonces.The default policy no longer includes |
Bug Fixes
| Description | Addresses |
|---|---|
Applied the Object Explorer tag filter to agent nodes.Tag-based filtering now behaves consistently across all node types. Previously agents were skipped by the filter and remained visible regardless of the selected tags. | |
Fixed an issue whereby customer-customised system-job schedules, jobenabled flags, and step code could be silently overwritten across reseed events. | 61176 |
Fixed an issue whereby an upgrade left a stale pem.jobstep row referencing the dropped function pem.purge_obsolete_data(), causing recurring job failures post-upgrade. | |
| Corrected the display of alert timestamps under non-UTC session settings. | |
Fixed an issue whereby a changed agent working directory could break subsequent operations because | |
Prevented duplicate server_group rows from being created when multiple agents register concurrently against the same server group. | |
Scoped the PGD raft leader-id alert per node group.PGD 5 raft subgroups elect leaders independently, so the alert now includes | 63967 |
Fixed a crash in the Performance Diagnostics Query Dashboard that fired when a collected sample had no matching active session.The wait-events timeline drill-down is also hardened against similar null cases. | |
Resolved dashboard tab titles on the backend so remotely monitored servers open the correct dashboard tab.Previously the tab could resolve to the wrong monitored server. | 64640 |
Fixed the Database cleanup upgrade script to use | 65129 |
Fixed a schedule with only a start date so it runs once at the specified time instead of firing every two minutes.Empty pattern arrays are no longer implicitly treated as wildcards. | |
Fixed an issue whereby agents could open two heartbeat connections (and two main-thread connections) instead of one.The heartbeat thread now waits for the old thread to exit before recreating it, so two threads holding separate connections can no longer coexist. | |
| Fixed an issue whereby agent registration could hang or fail with a lock timeout while the probe target materialized view was refreshing on large fleets. | |
| Fixed an issue whereby the Available Metric tree in Manage Charts (Line Charts) did not populate or allow selection, blocking metric selection for line-chart configurations. | |
Silenced a benign | |
Fixed an issue whereby empty agent, database, schema, or object name fields in SNMP trap generation produced "value(s) do not match OID(s)" errors at the notification receiver.An empty field previously collapsed the varbinding; a NULL placeholder is now substituted instead. | |
Disabled editing of the Alternate Code tab for system probes in the UI.The backend already silently rejected such edits; the SQL editor is now read-only for system probes so the UI affordance matches the actual permission. | |
| Fixed the column misalignment in the Grid View when column groups are present. | |
Fixed an issue whereby special characters (backslash, newline, carriage return, tab, and other control characters) in webhook payload values could produce invalid JSON and cause the webhook target to reject the payload.These characters are now correctly escaped when substituted into webhook payloads. | |
The REST API token endpoint now returns HTTP 403 with an actionable "GRANT pem_rest_api to ..." message when the caller is missing the required role, instead of a misleading HTTP 401. | |
| Fixed the Validate Binary Path modal so it renders its message as HTML instead of showing the raw markup to the user. | |
Fixed the Alert History Report selection semantics.Choosing Global + servers/agents now returns all matching alerts (previously only global alerts were returned); a Global selection no longer overrides other selections; Cleared alerts are preserved in the summary; and the output now includes target level, unit, and database/schema/object context columns. | |
| Fixed duplicate and unfiltered Alert Template options in the Profile dialog dropdown. | |
Fixed a crash on the Custom Dashboard page when a chart without a description was added.The missing description now renders safely instead of aborting the page load. | |
| Limited the markdown syntax accepted in chart descriptions so free-form markdown cannot break the rendering pipeline or introduce style bleed into the surrounding UI. | |
| The Manage Charts table now auto-refreshes when a new custom chart is created, so the newly-created chart appears without requiring a manual reload. | |
Fixed empty chart description tooltips for custom charts added to Custom Dashboards.The tooltip now shows the chart's description text. | |
| Chart description tooltips in the Custom Dashboard editor can now be hovered and scrolled, allowing users to read long descriptions in full. | |
Inherited table columns are now correctly read-only and non-removable across every entry point.The hardcoded OID and Definition-tab type restriction were removed and replaced with proper checks on both the | |
| Timestamps in alert and BDR nested detail tables are now localised to the user's session timezone. | |
| Fixed the Manage Profiles grid not extending to the panel bottom, and the error toast overlapping data rows. | |
Fixed an issue whereby non-2xx webhook responses were silently marked as a successful delivery.HTTP error response handling for webhook payloads now correctly reports non-2xx responses as failures. | |
Fixed login for Kerberos users whose email in the PEM directory is stored as | |
Fixed an issue whereby alert row expansion could collapse or jump to the wrong row when the underlying data refreshed.Row expansion is now bound to row identity rather than display position. | |
Fixed an issue whereby new server registrations could produce a template error because post_connection_sql was not set on server_optionsinsert. | |
Fixed the Dashboard tab restore path so that, after a browser refresh, the correct content is shown for each restored tab.Previously a restored tab could show the content from a different tab. | |
Fixed settings.get_tool_data returning HTTP 404 for dashboard tabs, which broke PEM tab restore on page reload. | |
Documented the required fields for probe_columns in the v17 OpenAPI spec and corrected the HTTP status returned for column validation failures from 500 to 400. | |
| Fixed the Auto Create toggle not appearing on Server-level and Agent-level alert templates. | |
Fixed alert template PUT returning HTTP 500 due to a positional dict-row index.Probe lookup is now keyed on column name instead of position. | |
Preserved job-step run history when a step is removed from a job.Deleted steps are now parked (marked as removed and disabled) so they disappear from the UI, while the job step log history survives for audit and troubleshooting. | |
Fixed schedule exceptions not appearing in the job dialog.The server sends exceptions as three arrays; these are now correctly converted for display when a job's properties are loaded, not only when saved. Also fixed saving exceptions on a newly-added schedule during a job update. | |
Fixed an issue whereby the os_info probe incorrectly populated os_start_time with a 12-hour based timestamp value. | |
| Fixed an issue whereby Reset Layout only reset the default workspace docker. | |
| Fixed an issue whereby the job properties tab showed Last Result as Failure for jobs that never ran. | |
| Fixed an issue whereby the Scheduled Task log file showed an "invalid date". | |
| Fixed an issue whereby the UI accepted a negative or zero value for agent heartbeat tolerance. | |
| Fixed an issue whereby some tree icons were missing. |
Deprecations
| Description |
|---|
Removed BART (Backup and Recovery Tool) support.All BART references have been retired from the agent, server schema, web UI, and packaging. |