HackerOne Disclosed Reports - 2026-05-08

0 Replies, 9 Views

Logo
Low
resolved

Private circle can be added to another circle via API despite visibility restriction


Bug reported by Dang Hung Vi was disclosed at May 8, 2026, 12:55 pm   |   Insecure Direct Object Reference (IDOR)

A vulnerability was discovered where private circles could be added to other circles via the API, despite visibility restrictions.


Logo
Low
resolved

Files drop share links for end-to-end encrypted folders allowed to drop files into other folders of the share owner


Bug reported by 0x0.eth was disclosed at May 8, 2026, 11:08 am   |   Insecure Direct Object Reference (IDOR)

Files drop share links for end-to-end encrypted folders allowed to drop files into other folders of the share owner.


Logo
Low
resolved

View-only guests could see deleted Collectives pages in the trashbin


Bug reported by _dha was disclosed at May 8, 2026, 8:35 am   |   Improper Access Control - Generic

A vulnerability was discovered where view-only guests could see deleted Collectives pages in the trashbin.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2026-05-08 - by hashXploiter - 4 hours ago



Users browsing this thread: 1 Guest(s)