HackerOne Disclosed Reports - 2026-10-08

0 Replies, 2 Views

Logo
Critical
resolved

Full Admin Takeover of R3 Limited's JFrog Artifactory - 292 Users, Corda Enterprise & CBDC Supply Chain Compromised


Bug reported by qw3rjö was disclosed at October 8, 2026, 7:30 pm   |   Improper Authentication - Generic

A critical authentication bypass vulnerability was identified in an enterprise artifact repository system. The vulnerability, with a CVSS score of 9.8, resulted from a default empty join key that allowed unauthenticated attackers to forge authentication tokens and gain full administrative access.

Through exploitation of this flaw, the following was confirmed:

- Full administrative access was obtained to the repository instance
- Approximately 292 user accounts were exposed
- Access was gained to 269 repositories, including 81 blockchain-related repositories and 4 digital currency repositories
- 262 access tokens were extracted, including 30 with administrative privileges
- Repository creation and deletion capabilities were demonstrated
- User account creation and deletion were performed
- Configuration decryption revealed plaintext credentials
- Cryptographic signing keys were extracted from the system

All test modifications were removed after confirmation of access. The vulnerability affected a system running version 7.133.16 with an enterprise license valid through November 2026.


Logo
Low
resolved

HackerOne Code: a live password reset token reaches Datadog RUM, and the same session records the account it unlocks


Bug reported by Sujit Jaunjal was disclosed at October 8, 2026, 10:21 am   |   Insufficiently Protected Credentials

A password reset token was transmitted to a real user monitoring service before the reset form was submitted. The token was passed as a query string parameter in the URL and recorded by the monitoring SDK without any redaction. The same monitoring session also captured the account identifier after the user authenticated. The monitoring service was configured with sampling at 100 percent and no URL sanitization callback, resulting in every reset token being recorded. The token was a live, single-use credential that could be used to reset any account without further authentication. A previously reported similar issue affecting a different telemetry service had been patched with path-specific redaction, but this left the same vulnerability open through an alternate monitoring sink that was not covered by that remediation.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)