Please rate how useful you found this document: 
No votes yet

Release Date: August 4th, 2026


This document contains release notes for ProcessMaker 3.9.11. Release Notes are cumulative, and document bug fixes and improvements associated with this release unless otherwise noted. A list of older ProcessMaker Release Notes is included at the end of this document.

Improvements

ProcessMaker 3.9.11 includes the following improvement:

  1. Added an environment variable to control session hijacking validation, providing administrators with greater flexibility when managing security behavior in supported environments.
    • Added disable_hijacking_verification, set to 0 by default.
    • Setting the value to 1 disables session hijacking validation.

Bug Fixes

ProcessMaker 3.9.11 includes the following bug fixes:

  1. Custom plugin validation messages no longer expose server file paths, and longer error details remain readable long enough for administrators to review why a plugin import was blocked.
  2. Code Scanner whitelist validation now displays the correct error message for trigger code that contains methods or functions not included in whitelist.ini, including the affected name and line number.

Previous Release Notes

Refer to the previous Release Notes from ProcessMaker versions 3.2 through 3.9.8: