Root cause
Export authorization diverged from report-view visibility. A file moved into an internal comment remained exportable. The researcher compared redacted display content with archive output; the vendor confirmed this was a distinct newly introduced issue.
Demonstrated impact
A user able to export a report could obtain team-only attachments. Vendor review additionally identified potential inline-attachment exposure, but found no evidence of malicious exploitation. This does not establish access to every private report.
Lessons for review
- Derive export contents from the same object-level policy used for interactive views.
- Treat referenced attachments as independently authorized objects, including after visibility changes.
Award and evidence
One report-level award includes the vendor’s expanded inline-attachment impact assessment. USD uses later platform-wide payment guidance reviewed in 2026, about ten years after the award; it does not prove individual settlement. The report explicitly distinguishes earlier report 182358.
Read the full public report in the cloud browser, including vendor summary, fix confirmation, award and disclosure timeline; corroborated award with the vendor retrospective. Reviewed currency guidance separately.
- No independent confirmation of cash settlement.
- Currency uses later platform-wide guidance, not an explicit currency code in the historical award event.
- Summary uses November 28 without timezone; the report and fix events display November 29 UTC.
- No patch implementation is disclosed.
Recorded timeline
- Published
- 2016-11-30explicit · Detailed report became public at the recorded disclosure event; later 2017 retrospective is not original publication.
- Public Disclosure
- 2016-11-30explicit
- Reported
- 2016-11-29explicit
- Awarded
- 2016-11-30explicit
- Fixed
- 2016-11-29explicit · Vendor fix-release comment at 04:36 UTC; researcher confirmation at 05:02 UTC. Summary says November 28 without a timezone; UTC timeline supplies the recorded date.
Sources and provenance
- Internal attachments can be exported via "Export as .zip" feature HackerOne and japz · reviewed 2026-10-03
- Celebrating $20M in Bounties with a Recap of Our Top 20 Up Voted Reports on Hacktivity johnk / HackerOne · reviewed 2026-10-03
- Vulnerability Disclosure Guidelines HackerOne · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.