- DATE:
- AUTHOR:
- CyberCloud Team
Release 28 August 2026
The July/August release brings several important additions to PentestPortal, including OWASP Top 10: 2025 support, a significantly expanded Jira CSV export, improved access management for Cyber Scans, and a new Ready for Retest workflow for findings.
We’ve also expanded audit log visibility, improved how reports and individual findings can be shared with customer contacts, and completed several technical upgrades behind the scenes. Alongside these features, this release includes a broad set of fixes around permissions, customer access, Nessus/Nmap imports, reporting, and role synchronization.
Features & Improvements 
PP-563: OWASP Top 10: 2025 support
PentestPortal now supports the OWASP Top 10: 2025 classification.
Application security findings can be linked to the latest OWASP Top 10 standard, keeping classifications and reporting aligned with the newest version.
PP-715: Manage customer contacts for Cyber Scans
Following the introduction of pentest-level RBAC, regular customer contacts no longer automatically have access to Cyber Scans. Previously, this meant Cyber Scans were primarily accessible to Customer Functional Managers.
Customer contacts can now also be explicitly added to and managed for individual Cyber Scans, providing more granular control over who can access scan results.
PP-691: Migration to Mongoose 9
PentestPortal has been migrated to Mongoose 9.
As part of this technical upgrade, we updated hooks, query types, UUID handling, update pipelines and other affected functionality. Field-level encryption, attachments and user-related functionality were also verified against the new version.
While mostly an under-the-hood improvement, this keeps the platform's technical foundation current and maintainable.
PP-745: Extended Jira CSV export
The Jira CSV export has been significantly expanded with additional finding metadata, making it easier to automate Jira workflows and perform further analysis outside PentestPortal.
The export can now include additional information such as:
Finding creation date and report finalization date
Risk, impact and likelihood, including retest values where applicable
CVSS score
Finding ID
Recommendation
Affected targets
Finding category
OWASP classifications
CWE classifications, including number and short title
This provides teams with richer data for reporting, trend analysis, automation and Jira-based security workflows.
PP-743: Immediate redirect after approving a quality requirement
After approving a quality requirement, users are now immediately returned to the quality requirements overview.
Previously, the automatic redirect depended on at least one comment being present. That requirement has been removed, making the approval workflow more predictable.
PP-742: Report access for contacts without a mobile number
Sharing reports and findings has been improved for customer contacts without a registered mobile phone number.
When a customer contact can already log in to PentestPortal, they can now be notified by email and view the report directly through the portal instead of relying on SMS delivery.
This functionality has also been extended to individual findings. To prevent accidental sharing, individual findings cannot be sent while either the pentest or finding is still in Concept status.
PP-738: New “Ready for Retest” finding status
Customers can now indicate that a finding is Ready for Retest.
This creates a clearer workflow between remediation and retesting: once a customer has addressed a finding, they can explicitly signal that it is ready for the pentester to verify.
PP-744: Risk status permissions for Customer Functional Managers
Users with the Customer Functional Manager role now automatically receive permission to update finding statuses.
This aligns risk management permissions with the responsibilities of the functional manager role.
PP-716: Audit log available to customer contacts
Pentest audit logs are no longer limited to Customer Functional Managers.
Customer contacts who have been granted access to a pentest can now also view its audit log, providing greater transparency into relevant activities and changes.
Bug Fixes
PP-750: Customer risk page remains empty - Fixed an issue where the risk detail page could remain empty when opened from the customer view.
PP-748: Reports and findings cannot always be sent - Fixed inconsistent delivery behavior when sending reports or individual findings to contacts without a phone number, including for retests.
PP-746: Typecheck fixes - Resolved several TypeScript typing issues and improved type consistency to help catch problems earlier during development and builds.
PP-741: Duplicate contact persons on pentests - Fixed an issue that could result in duplicate customer contacts being stored on a pentest and ensured removal correctly updates both roles and pentest contact data.
PP-737: Frontend permissions not synchronized after creating a pentest - Fixed a connection issue that could leave the frontend with outdated permissions after a server restart. Newly created pentests can now be accessed immediately when the user has the required rights.
PP-734: Approver name missing from approved quality requirements - The name of the person who approved a quality requirement is displayed correctly again.
PP-733: Customer Functional Manager permissions not applied consistently - Fixed cases where a Customer Functional Manager could unexpectedly lose access to a pentest. The pentest-level login setting now also correctly reflects the broader Functional Manager role.
PP-732: Adding a Pentester IP could freeze the frontend - Resolved an inconsistent permission check that could cause the interface to hang when adding a Pentester IP. The permission handling now correctly follows the updated RBAC model.
PP-726: Nessus/Nmap upload permissions for customer users - Refined permissions around scope management and Nessus/Nmap imports. Customers may still manage scope where permitted, while Nessus and NMAP uploads are now controlled separately with the appropriate permissions.
PP-720: Re-adding removed users - Improved handling of previously removed users. Deleted users are no longer incorrectly shown in user selection lists, and restoring an existing Azure-backed user is handled correctly.
PP-651: Large Nessus imports could crash the portal - Large Nessus files containing a huge number of targets could trigger too many simultaneous requests and crash the interface. Imports are now processed with a maximum number requests in parallel for improved stability.
PP-747: Incorrect finding ID in email subject - Fixed an issue where sending a specific finding number, could result in an incorrect placeholder such as
WA-Xappearing in the email subject.
We believe that PentestPortal will greatly enhance the experience of individual penetration testers, penetration testing firms and enterprises conducting their own pentests and that PentestPortal contributes to more efficient and effective penetration testing. Your feedback is invaluable in helping us improve and tailor the software to meet your needs.
Thank you for choosing our software, and we look forward to hearing your thoughts on this exciting new release!