HackerOne Disclosed Reports - 2026-02-28

0 Replies, 34 Views

Logo
Medium
resolved

2FA requirement bypass when inviting team members


Bug reported by Youssef AboHashish was disclosed at February 28, 2026, 8:55 pm   |   Improper Access Control - Generic

The application's requirement for users to enable 2FA before sending team invitations was bypassed by modifying client-side responses. This allowed invitations to be sent without enabling 2FA, defeating the security requirement.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)