Dark C0d3rs
HackerOne Disclosed Reports - 2026-01-06 - Printable Version

+- Dark C0d3rs (https://darkcoders.wiki)
+-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log)
+--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports)
+--- Thread: HackerOne Disclosed Reports - 2026-01-06 (/Thread-HackerOne-Disclosed-Reports-2026-01-06)



HackerOne disclosed reports - 2026-01-06 - hashXploiter - 01-07-2026

Logo
Medium
resolved

Non-Production API Endpoints for the AI Ops Service Fails to Log to CloudTrail Resulting in Silent Permission Enumeration


Bug reported by Nick Frichette (Datadog) was disclosed at January 6, 2026, 6:00 pm   |   Insufficient Logging

The vulnerability found that there are 5 non-production endpoints for the AI Ops service that can be used with standard IAM credentials and do not log to CloudTrail. While the endpoints do not appear to provide access to customer partition data, they can be used for permission enumeration without leaving an audit trail.