Bug Bounty Channel
15K subscribers
2 photos
11.5K links
All bug bounties here.
Download Telegram
🏦 SingleStore Report
📝 Title: Insecure Direct Object Reference \(IDOR\) allows creating folders.
🔍 Reporter: bl4ck- (Ali Abbas)

📋 Details:
📊 Status: resolved
Severity: Low
🎯 CWE: Insecure Direct Object Reference \(IDOR\)
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-01 17:41:16 UTC
📝 Created: 2025-09-22 06:00:57 UTC
🏦 SingleStore Report
📝 Title: Delete any folder for any user within the organization
🔍 Reporter: bl4ck- (Ali Abbas)

📋 Details:
📊 Status: resolved
Severity: Low
🎯 CWE: Insecure Direct Object Reference \(IDOR\)
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-01 17:39:22 UTC
📝 Created: 2025-09-22 05:08:14 UTC
🔥1
🏦 SingleStore Report
📝 Title: Privilege Escalation – Access to the Alert Subscribers page for users with low privileges
🔍 Reporter: bl4ck- (Ali Abbas)

📋 Details:
📊 Status: resolved
Severity: Low
🎯 CWE: Privilege Escalation
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-01 17:36:56 UTC
📝 Created: 2025-09-22 03:30:31 UTC
1👍1
🏦 Nintendo Report
⚠️ Title: Splatoon 3 In-Match Integrity Bypass via Consensus Reflection Attack on Unordered Peer Submission
🔍 Reporter: hana2736 (Hana)

📋 Details:
📊 Status: resolved
Severity: High
🎯 CWE: Client-Side Enforcement of Server-Side Security
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-02 01:26:11 UTC
📝 Created: 2026-02-17 20:01:19 UTC
1
🏦 Nintendo Report
Title: \[Splatoon 3\ Kick other players with NplnLogin message](https://hackerone.com/reports/3813932)
🔍 Reporter: alzxk11 (Alex)

📋 Details:
📊 Status: resolved
Severity: Medium
🎯 CWE: Improper Access Control - Generic
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-02 01:25:44 UTC
📝 Created: 2026-06-20 09:49:38 UTC
1
🏦 8x8 Report
📝 Title: jitsi-call-analytics: Unauthenticated arbitrary file write via path traversal in \`/api/v1/uploads/analyze\`
🔍 Reporter: r1skr1der (zhixin)

📋 Details:
📊 Status: resolved
Severity: Low
🎯 CWE: Path Traversal
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-02 15:41:33 UTC
📝 Created: 2026-01-03 02:38:16 UTC
🏦 Yelp Report
Title: Yelp for Business: locked Email field silently editable via API
🔍 Reporter: 0xmanticore (Saleh Elsayed)

📋 Details:
📊 Status: resolved
Severity: Medium
🎯 CWE: Client-Side Enforcement of Server-Side Security
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-02 15:36:44 UTC
📝 Created: 2026-05-28 09:34:40 UTC
🏦 AWS VDP Report
Title: Non-Production API Endpoints for the Amazon S3 Tables Service Fails to Log to CloudTrail Resulting in Silent Permission Enumeration
🔍 Reporter: nick_frichette_dd (Nick Frichette \(Datadog\))

📋 Details:
📊 Status: resolved
Severity: Medium
🎯 CWE: Insufficient Logging
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-02 17:51:21 UTC
📝 Created: 2026-06-03 17:00:17 UTC
1👏1
🏦 Shopify Report
📋 Title: admin.shopify.com: Shopify Flow continues sending internal emails to a configured recipient after the staff author is removed
🔍 Reporter: abahack (Emmanuel Abah)

📋 Details:
📊 Status: informative
Severity: None
🎯 CWE: Not Specified
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-03 18:50:06 UTC
📝 Created: 2026-03-26 10:49:30 UTC
2👏1
🏦 Basecamp Report
Title: Any installed app can force immediate logout and persistent DOS of authenticated Basecamp sessions via unprotected exported StartActivity
🔍 Reporter: zerodaysec_xyz (Z)

📋 Details:
📊 Status: resolved
Severity: Medium
🎯 CWE: Improper Access Control - Generic
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-04 11:05:36 UTC
📝 Created: 2026-05-27 08:46:53 UTC
4
🏦 AWS VDP Report
⚠️ Title: OS Command Injection in \`aws-cdk-lib\` NodejsFunction via Unsanitized \`OsCommand\` Helper \(Supply Chain RCE\)
🔍 Reporter: kaporia (Kaporia515)

📋 Details:
📊 Status: resolved
Severity: High
🎯 CWE: OS Command Injection
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-06 17:48:30 UTC
📝 Created: 2026-03-30 12:48:07 UTC
4
🏦 AWS VDP Report
Title: Kiro IDE Stores Auth Tokens with World-Readable Permissions \(0644\)
🔍 Reporter: mistercloudsec (Sergio Garcia)

📋 Details:
📊 Status: resolved
Severity: Medium
🎯 CWE: Incorrect Default Permissions
🔢 CVE: CVE-2026-11931

Timeline:
🔓 Disclosed: 2026-07-09 15:31:28 UTC
📝 Created: 2026-03-26 20:58:40 UTC
2👍1
🏦 SingleStore Report
⚠️ Title: SELECT ... INTO OUTFILE does not enforce the FILE WRITE privilege unprivileged arbitrary file write on the server
🔍 Reporter: bisht-ji (No name)

📋 Details:
📊 Status: resolved
Severity: High
🎯 CWE: Missing Authorization
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-13 19:35:07 UTC
📝 Created: 2026-06-03 20:54:07 UTC
1
🏦 AWS VDP Report
Title: bedrock-mantle.api.aws accepts Bedrock API keys outside the IAM Deny, CloudTrail signal, and invocation logging AWS publishes for Bedrock keys
🔍 Reporter: mistercloudsec (Sergio Garcia)

📋 Details:
📊 Status: resolved
Severity: Medium
🎯 CWE: Insecure Default Initialization of Resource
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-14 18:52:27 UTC
📝 Created: 2026-04-28 21:50:53 UTC
🏦 Basecamp Report
📝 Title: Stored XSS on Trix Editor version latest \(2.1.16\) - Sanitizer Bypass
🔍 Reporter: newbiefromcoma (jeeva)

📋 Details:
📊 Status: resolved
Severity: Low
🎯 CWE: Cross-site Scripting \(XSS\) - Stored
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-14 19:26:37 UTC
📝 Created: 2026-03-02 22:01:38 UTC
🏦 AWS VDP Report
Title: Bedrock AgentCore Starter Toolkit Creates Gateway IAM Roles Without Confused Deputy Protections
🔍 Reporter: mistercloudsec (Sergio Garcia)

📋 Details:
📊 Status: resolved
Severity: Medium
🎯 CWE: Incorrect Permission Assignment for Critical Resource
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-15 15:11:59 UTC
📝 Created: 2026-03-27 19:33:14 UTC
2
🏦 GitHub Report
Title: Able to bypass authorization logic and gain more access then intended
🔍 Reporter: vaib25vicky (v1c7)

📋 Details:
📊 Status: resolved
Severity: Medium
🎯 CWE: Not Specified
🔢 CVE: CVE-2026-9106

Timeline:
🔓 Disclosed: 2026-07-15 16:35:57 UTC
📝 Created: 2026-05-05 07:30:36 UTC
1
🏦 Rocket.Chat Report
Title: Stored XSS in Rocket.Chat HTML File Export — Unauthenticated Entry via LiveChat
🔍 Reporter: olidayw (Denis Rostilov)

📋 Details:
📊 Status: resolved
Severity: Medium
🎯 CWE: Cross-site Scripting \(XSS\) - Stored
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-16 05:02:04 UTC
📝 Created: 2026-06-03 13:37:47 UTC
1
🏦 Monero Report
📝 Title: Restricted RPC leaks alternative block hashes via /get\_alt\_blocks\_hashes
🔍 Reporter: int0ha_ (Connor Carro)

📋 Details:
📊 Status: resolved
Severity: Low
🎯 CWE: Improper Access Control - Generic
🔢 CVE: None

Timeline:
🔓 Disclosed: 2026-07-20 00:15:10 UTC
📝 Created: 2026-05-15 17:06:05 UTC
1