CLM for Salesforce October25.26.0706 Release Notes
In these release notes, you can find packages, requirements, enhancements, and fixed and known issues for the CLM October25.26.0706 release. For documentation updates, see What's New in CLM Documentation.
This documentation may describe optional enhancements for which you have not purchased a license; therefore your solution or implementation may differ from what is described here. Contact your customer success manager (CSM) or account executive (AE) to discuss your specific enhancements and licensing.
Packages
The following packages and dependencies are required to upgrade to this release and use its enhancements. These are the minimum required versions; later versions are also supported. Prerequisites for each enhancement can be found in its documentation. Packages marked (New) are new for this release.
You can register your org for the Conga Upgrade Program, an automated tool that keeps all Conga managed packages in your Salesforce org (production or sandbox) updated to the latest versions. For more information, see Registering for Conga Upgrade Program.
| Package | Latest Certified Version | |
|---|---|---|
| Name | Number | |
Conga Contract Lifecycle Management (Changed) | 16.2.799.6 | 16.799.6 |
Conga Base Library (Changed) | 6.2.285.4 | 6.285.4 |
Adobe Sign | v25.6 | 25.6 |
Conga for Salesforce | 2.2.12 | 2.12 |
Conga CLM Adobe Sign Integration | 10.73.10 | 10.1.73 |
Conga DocuSign API | 8.142.28 | 8.1.142 |
System Requirements and Supported Platforms
For requirements and recommendations to consider before installing the Conga product suite, see the System Requirements and Supported Platforms Matrix.
Enhancements
There are no enhancements in this release.
Fixed Issues
The following issues are fixed in this release. If any actions are required, they will be listed in this table.
| Case Number | Conga Internal ID | Description |
|---|---|---|
| NA | CONTRACTS-42354 |
A potential security vulnerability is identified in the deprecated Apttus__OCCResource public resource, where the serverurl query parameter in /resource/Apttus__OCCResource/webBasedRichTextEditor/index.html is passed directly to document.write(). This behavior could expose the application to DOM-based Cross-Site Scripting (XSS) risks if malicious input is supplied through the URL. The issue is found during a customer security review and required remediation to eliminate the potential attack vector associated with the deprecated resource. |
Known Issues
There are no known issues in this release.
DOC ID: CLMOCT25PRN20260706
