HackerOne Disclosed Reports - 2026-01-02

0 Replies, 98 Views

Logo
Low
resolved

The role "CI-driven scan initiator" provides excessive read access


Bug reported by Osama Hamad was disclosed at January 2, 2026, 9:32 am   |   Privilege Escalation

The reporter noticed that all authenticated users were able to access certain non-sensitive information such as metadata about third-party integrations. This was found to be by design, and the documentation was updated to clarify the information available to all authenticated users.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: