Release Notes

MetaDefender Managed File Transfer 3.11.4

Release Date: 06, July 2026

MFT 3.11.4 delivers user group access controls for folder and sharing management, configurable Login Page Announcements, an expanded SFT Database Configuration Tool, and over 55 bug fixes and reliability improvements.

New Features & Enhancements


Security

One-Time Upload Token

Generate a single-use token for file upload authorization, enabling controlled external upload access without exposing user credentials or persistent sharing links.

SSO Admin Role Assignment

Assign Readonly Administrator and Helpdesk Administrator roles to users via SSO group claims, extending automatic role provisioning to administrative role types.

SSO Group as Supervisor Approver

Assign an SSO group as the supervisor for approval workflows, enabling approval responsibility to follow group membership without per-user manual configuration.


User Management

User Group Access Controls

Configure folder, sharing, and Trash permissions at the group level, restricting actions for specific user groups without per-user configuration.

  • Folder creation — prevent group members from adding folders in shared spaces where only file uploads are permitted

  • Folder renaming — maintain consistent folder structures by disabling rename for selected groups

  • File and folder sharing — enforce group-level data distribution policies

  • Trash access — hide the Trash section for groups that do not require permanent deletion

External User Interface Restrictions

Hide the Sharing panel and My Files section for External Users, presenting a scoped interface limited to their permitted access areas.

Minor Enhancements

  • Ad Hoc Guest Sharing Reliability — guest accounts created on-the-fly during file sharing are processed through a consolidated creation flow, reducing edge cases in shared space provisioning.


Automation

Path-Based Transfer Filtering

Filter file transfer operations by path patterns to restrict, allow, or redirect transfers based on source or destination path criteria.

MFT-to-MFT TCP Connection Limit

Configure the maximum number of concurrent TCP connections for MFT-to-MFT transfers over one-way network diodes, preventing connection exhaustion in high-throughput environments.


Integrations

Guest Sharing Email Template

Invitation emails sent to guest users created during file sharing use a dedicated template, providing clear first-access context separate from standard sharing notifications.

File Deletion Email Notification

Receive an email notification when a file is moved to Trash, keeping users informed of deletions affecting shared or monitored content.


Platform

HA Controller Live Configuration Apply

Configuration changes saved in the HA Controller are applied to the cluster immediately without requiring a service restart, reducing planned downtime for HA updates.

SQL HA Connection String Reconfiguration

Reconfigure the SQL connection string for MFT in an HA deployment without running the installer, reducing downtime when updating database connection settings.

Minor Enhancements

  • LibreOffice Preview Engine Update — preview Office documents using LibreOffice 26.2.1, incorporating upstream security fixes and improved compatibility with recent document formats.

  • HA Configuration Tool UI Refinements — the HA Configuration Tool incorporates design updates for improved clarity and visual consistency with the MFT administrative interface.


Administration

File Status on Post-Action Failure

Files processed successfully but with a failed post-action display an accurate availability status, distinguishing a completed transfer from a post-processing error.

Login Page Announcement

Configure a custom announcement message that displays on the MFT login page, communicating maintenance windows or access notices to all users before authentication.

  • Announcement display — administrator-configured messages appear as banners on the login page before sign-in

Column-Level Table Filtering

Filter table data at the column level across MFT list views, enabling targeted searches by specific field values without affecting other column displays.

Minor Enhancements

  • SharePoint Add-in Removal — the legacy SharePoint Add-in option is removed from the MFT interface, directing SharePoint integration to the supported SharePoint connector path.


Monitoring

Usage Report

Report Aggregated Data — anonymized statistics, measures, and usage information as defined in the OPSWAT Terms of Service — to help OPSWAT improve its products.


File Storage

Flexible File Download Format

Download multiple files as a single ZIP archive or as individual files, choosing the format best suited to the recipient's workflow at the time of download.


Bug Fixes & Improvements


Security Fixes

SSO Update Button Permission

The SSO configuration Update button is disabled for Readonly Administrators, consistent with their non-write access to authentication settings.

REST API Denial of Service Vulnerability

The MFT REST API applies request rate limiting and input validation controls to close a Denial of Service exposure path in the REST layer.

Database Tool SQL Auth Certificate Trust

The SFT Database Configuration Tool enforces SQL Server certificate validation in SQL authentication mode rather than unconditionally trusting self-signed certificates.


Stability Fixes

Automation Job Memory Growth

The Next service memory usage returns to baseline after prolonged automation job execution, without requiring a service restart to recover.

HA HTTPS Login Page Loading

The MFT login page loads correctly when both the HA Controller and MFT nodes are configured to run in HTTPS mode.

Archive Download Job Creation

Creating archive download jobs completes successfully without encountering configuration or initialization errors.

Upload Request Stream Disposal

File upload request streams are disposed correctly after transfer completion, preventing resource accumulation during high-volume upload operations.

Job Recovery After SQL Connectivity Loss

Automation jobs interrupted by a transient SQL connectivity loss release their in-memory lock and resume processing rather than remaining permanently stuck.

SFT Database Configuration Tool Installation

Installation, upgrade, and rollback operations complete without unexpected failures across Windows Authentication and SQL authentication modes.

  • Windows Authentication — the tool completes Windows Auth configuration without a DLL not found error

  • Upgrade database connection — installer upgrades complete the database connection step without failing in environments with custom SQL parameters

  • Rollback state restoration — rolling back a configuration change restores the original state, leaving MFT fully operational


Reliability Improvements

File Classification Pull Job Status

MFT pull jobs with file classification report an accurate completion status reflecting whether a file was transferred, rather than showing success when no transfer occurred.

Permanent File Deletion Audit Log

Permanent file deletions complete without generating repeated error log entries about missing metadata, and audit records for deleted files are removed from the file audit correctly.

MFT-to-MFT Transfer Logging

MFT-to-MFT file transfers emit detailed log entries for each transfer step, improving diagnostic visibility for transfer failures and latency issues.

SMB Pull Connection Loss Handling

SMB Pull jobs complete successfully without reporting a false client disconnection failure when the SMB connection remains active throughout the transfer.

SQL Query Performance

Database query execution for common MFT operations is optimized, reducing latency for high-frequency administrative and transfer workflows.

Expired OTP Audit Logging

Attempts to authenticate with an expired OTP code are recorded in the audit log, providing a complete record of failed authentication events.

Shared Space Reliability

Shared content is accessible and deliverable across all sharing configurations and user types.

  • Shared With Me downloads — files listed in the Shared With Me view download successfully across all permission levels

  • Ad hoc guest access — guest users created on-the-fly during file sharing access the shared space without encountering a user collection validation error


Behavior Corrections

Sharing Disabled State Response

Accessing sharing endpoints when sharing is globally disabled returns a handled response rather than a 500 server error.

Setup Wizard Rate Limit Configuration

Rate limit values configured during the Setup Wizard via the spark ignition file are applied to the running MFT instance.

SFTP SSH Key Passphrase Error Message

SFTP connections configured for SSH key-only authentication reject passphrase-protected keys with a password required message rather than an incorrect key error.

HA Controller Upgrade Directory Enforcement

Upgrading the HA Controller retains the original installation directory and does not present an option to select a different path during the upgrade process.

External User File Sharing Permission

External users with the Allow External Users to Share Files setting enabled can share files as expected, consistent with the configured policy.

Pull to User CSV Special Character Support

CSV recipient files for SFTP Pull to User jobs process entries containing non-alphabetic and special characters without parsing errors.

Email Template User Name Display

Notification emails display the recipient's username or display name as defined in the email template, rather than falling back to a system-generated default.

Orphaned Required Question Upload Block

Required questions in secure web form sections with no parent section no longer block file uploads for non-administrator users.

Duplicate Section Name Handling

Secure web form sections with identical names are displayed as distinct sections rather than merged into a single combined view.

File Scan State on Core Unavailability

Files enter a correct error state when the scanning service returns a 503 response, rather than remaining indefinitely in the Processing - Scanning state.

File Deletion With Trash Disabled

Users in groups with Trash disabled can delete files directly, rather than encountering a deletion error caused by the absence of the Trash destination.

No-Email User Warning List Scope

The warning list for users without configured email addresses excludes Central Management-managed accounts and third-party user accounts, which do not require local email configuration.

SFT Database Configuration Tool Behavior

Configuration and rollback operations in the SFT Database Configuration Tool produce accurate results across all scenarios.

  • Password special characters — accepts passwords containing special characters, supporting the full range permitted by SQL Server

  • Log on as account rollback — restores the original Windows account for MFT services to its pre-change state after rollback

  • Rollback service notification — completes rollback without reporting a false mftHelper service failure when the service restarts successfully

File Security Report Filters

File Security Report filters behave correctly across all filter types, value combinations, and character sets.

  • Filter persistence — active filters are preserved when navigating away and returning to the page

  • OR logic — combining values in the Origin column returns files matching any of the selected values

  • Non-Latin characters — file classification filter values with accented or non-Latin characters are processed correctly

  • Date range boundary — the to date includes records on the specified date, using inclusive boundary behavior


UI & Usability Fixes

  • Supervisor Level 2 Dropdown — the supervisor approval dropdown for level 2 in mixed step-based approval workflows opens and responds to selection correctly.

  • Automation Job Target MFT Field State — input fields for MFT-specific job configuration are disabled when no target MFT is selected.

  • Upload Questionnaire Navigation Button — multi-step upload questionnaires display the Next button at intermediate steps and the Complete Upload button only at the final step.

  • Upload Question Column Header Display — pending approval views show the correct column header rather than the question text in the column label position.

  • Automation Job Group User View — automation jobs display a consistent configuration view for users who are members of a group.

  • Blank Username Validation — automation job usernames containing only whitespace characters fail validation with a clear error message.

  • HA Configuration Tool Error Styling — error messages in the HA Configuration Tool are displayed in red, providing the expected visual feedback for validation and runtime failures.

  • Audit Filter Dropdown Behavior — filter dropdowns on the Audit page open and display available options correctly across all filtering categories.

  • Email OTP Authentication UI — the email OTP authentication flow includes updated interface elements for improved clarity and consistency.

  • Automation Job Period Input Validation — the Set Period field rejects negative and decimal number inputs, accepting only positive integer values.

  • AD User Notification Email GUI Update — adding a notification email address for Active Directory users reflects the update in the interface immediately without a page reload.

  • Automation Job UI Rendering — automation job configuration pages render correctly across all job types, displaying complete form fields and controls.

  • Database Tool --trust-server-certificate Help — the SFT Database Configuration Tool command-line help displays valid argument descriptions for the --trust-server-certificate flag.

  • Database Tool --encrypt Help — the SFT Database Configuration Tool command-line help displays valid argument descriptions for the --encrypt flag.

  • Database Tool Service Account Validation — the tool reports a clear error when the selected Windows account is not a member of the Log on as a service security group.

  • Pull to User Path Configuration Visibility — the path configuration field is hidden when Enable sync all users is active, displaying only settings relevant to the selected mode.

  • MFT Pull Toggle Label Clarity — the MFT Pull to User toggle displays a label that accurately reflects the current operational mode.

  • SFTP Push Option Label Clarity — SFTP Push job configuration labels are updated to accurately describe each option's behavior.

  • Malware Detection Count Filter Display — the Malware detection count filter on the File Security Report does not present -1 as a selectable filter value.

  • Secure Web Forms General Availability — Secure Web Forms is available as a generally available feature, with the BETA designation removed from all UI surfaces.


On This Page
Release NotesMetaDefender Managed File Transfer 3.11.4New Features & EnhancementsBug Fixes & ImprovementsSecurityUser ManagementAutomationIntegrationsPlatformAdministrationMonitoringFile StorageSecurity FixesStability FixesReliability ImprovementsBehavior CorrectionsUI & Usability FixesOne-Time Upload TokenSSO Admin Role AssignmentSSO Group as Supervisor ApproverUser Group Access ControlsExternal User Interface RestrictionsPath-Based Transfer FilteringMFT-to-MFT TCP Connection LimitGuest Sharing Email TemplateFile Deletion Email NotificationHA Controller Live Configuration ApplySQL HA Connection String ReconfigurationFile Status on Post-Action FailureLogin Page AnnouncementColumn-Level Table FilteringUsage ReportFlexible File Download FormatSSO Update Button PermissionREST API Denial of Service VulnerabilityDatabase Tool SQL Auth Certificate TrustAutomation Job Memory GrowthHA HTTPS Login Page LoadingArchive Download Job CreationUpload Request Stream DisposalJob Recovery After SQL Connectivity LossSFT Database Configuration Tool InstallationFile Classification Pull Job StatusPermanent File Deletion Audit LogMFT-to-MFT Transfer LoggingSMB Pull Connection Loss HandlingSQL Query PerformanceExpired OTP Audit LoggingShared Space ReliabilitySharing Disabled State ResponseSetup Wizard Rate Limit ConfigurationSFTP SSH Key Passphrase Error MessageHA Controller Upgrade Directory EnforcementExternal User File Sharing PermissionPull to User CSV Special Character SupportEmail Template User Name DisplayOrphaned Required Question Upload BlockDuplicate Section Name HandlingFile Scan State on Core UnavailabilityFile Deletion With Trash DisabledNo-Email User Warning List ScopeSFT Database Configuration Tool BehaviorFile Security Report Filters