vulns.co
/
GKData.io MCP

Bugcrowd · 3 min read

Okta

Paid Bounty · $100 - $75,000

Open current program Reviewed policy

What this record establishes

Reviewed policy

An individually reviewed public policy is linked to this program page.

Read the reviewed policy profile →

Official directory card labeled Bug Bounty. Monetary reward displayed. Program policy and submission status not reviewed.

Published asset scope

Snapshot captured 2026-10-03. Scope status: Captured.

In scope · 21 published rows
AssetTypeGroup / eligibility
bugcrowd-pam-###.oktapreview.comwebsiteOkta Privileged Access
bugcrowd-pam-###.pam.oktapreview.comwebsiteOkta Privileged Access
https://bugcrowd-pam-###.workflows.oktapreview.comwebsiteOkta Workflows
Desktop MFA for WindowsotherOkta Device Access
Desktop MFA for macOSotherOkta Device Access
Password Sync for macOSotherOkta Device Access
support.okta.comPublished location: https://support.okta.comwebsiteOkta Support Portal (support.okta.com)
https://bugcrowd-pam-###.at.oktapreview.comwebsiteAtSpoke (Okta Access Requests) (New)
https://bugcrowd-pam-###.oktapreview.comwebsiteOkta (OIE) In-Scope Targets (New)
Okta Verify FastpassPublished location: https://www.okta.com/fastpass/otherOkta (OIE) In-Scope Targets (New)
https://bugcrowd-pam-###-admin.oktapreview.comwebsiteOkta (OIE) In-Scope Targets (New)
Advanced Server Access (ASA) / (ScaleFT)Published location: https://www.okta.com/products/advanced-server-access/websiteAdvanced Server Access
http://app.scaleft.com/websiteAdvanced Server Access
Advanced Server Access Client / AgentsPublished location: https://help.okta.com/asa/en-us/Content/Topics/Adv_Server_Access/docs/client.htmotherAdvanced Server Access
Okta Verify (iOS)Published location: https://apps.apple.com/us/app/okta-verify/id490179405iosOther In-Scope Targets
Okta Verify (Android)Published location: https://play.google.com/store/apps/details?id=com.okta.android.auth&hl=en_US&gl=USandroidOther In-Scope Targets
Okta Verify (Mac OS)Published location: https://apps.apple.com/us/app/okta-verify/id490179405otherOther In-Scope Targets
Okta Verify (Windows)otherOther In-Scope Targets
Okta On-Prem Agents ( AD, LDAP, RDP, IWA )otherOther In-Scope Targets
Okta Agent WindowsPublished location: https://help.okta.com/en/prod/Content/Topics/Adv_Server_Access/docs/sftd-windows.htmotherOther In-Scope Targets
Okta Browser Plugin (IE / Firefox / Chrome)Published location: https://help.okta.com/en/prod/Content/Topics/Settings/download-browser-plugin.htmotherOther In-Scope Targets
Out of scope · 18 published rows
AssetTypeGroup / eligibility
personal.trexcloud.comwebsiteOkta Personal
bugcrowd-%username%-1.oktapreview.comwebsiteOkta (Classic) In-Scope Targets
bugcrowd-%username%-2.oktapreview.comwebsiteOkta (Classic) In-Scope Targets
*.okta.comwebsiteOut of Scope Targets
*.trexcloud.comwebsiteOut of Scope Targets
login.okta.comwebsiteOut of Scope Targets
pages.okta.comwebsiteOut of Scope Targets
developer.okta.comwebsiteOut of Scope Targets
trust.okta.comwebsiteOut of Scope Targets
www.okta.com (static site)websiteOut of Scope Targets
https://scaleft.comwebsiteOut of Scope Targets
https://app.scaleft.com/p/signupwebsiteOut of Scope Targets
https://github.com/oktadevwebsiteOut of Scope Targets
Backend Okta non-app infrastructureotherOut of Scope Targets
Network layer issuesotherOut of Scope Targets
AtSpoke - Okta Workflows actions in access requestswebsiteOut of Scope Targets
AtSpoke - Entitlement bundles as a resource in access requestswebsiteOut of Scope Targets
Anything not explicitly called out above as in-scopeotherOut of Scope Targets

Capture limits

  • Brief displays May 22, 2026 as its update date. Older embedded announcements are not proof of current scope or bonus eligibility.
  • USD normalization uses Bugcrowd accounting documentation; the brief itself displays dollar signs.
  • The linked primary Vulnerability Disclosure Policy PDF could not be retrieved by the text tool. Supplemental terms were read and display July 22, 2019. Review is not a complete legal-terms audit.
  • No authenticated submission was attempted. Product-specific setup details and asset inventories are deliberately omitted; live terms prevail.
  • Linked announcement and change-log archives were not separately read; announcement facts above come from notices displayed within the reviewed brief.
  • Published target group rows were captured; group descriptions, rules and exclusions may further narrow permitted research.

Live policy and platform eligibility still require review.

Sources and collection identity

  1. Official program page Primary source · reviewed 2026-10-03
  2. Published scope source Primary source · reviewed 2026-10-03

Appears in Discovery, Bounty, Bugcrowd, Profile. No identity match is inferred from a shared company name.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software