vulns.co
/
GKData.io MCP

AZAuthorization and tenant boundaries · 2 min read

HackerOne exports omitted internal-attachment authorization

HackerOne awarded $12,500 for internal attachments exposed through report export in 2016. Its enduring lesson for 2026 applications is that export and interactive views must enforce the same visibility policy.

Read the primary source AZAuthorization and tenant boundariesReviewed 2026-10-03

Root cause

Export authorization diverged from report-view visibility. A file moved into an internal comment remained exportable. The researcher compared redacted display content with archive output; the vendor confirmed this was a distinct newly introduced issue.

Demonstrated impact

A user able to export a report could obtain team-only attachments. Vendor review additionally identified potential inline-attachment exposure, but found no evidence of malicious exploitation. This does not establish access to every private report.

Lessons for review

  • Derive export contents from the same object-level policy used for interactive views.
  • Treat referenced attachments as independently authorized objects, including after visibility changes.

Award and evidence

USD 12,500Bug Bounty · Platform Confirmed

One report-level award includes the vendor’s expanded inline-attachment impact assessment. USD uses later platform-wide payment guidance reviewed in 2026, about ten years after the award; it does not prove individual settlement. The report explicitly distinguishes earlier report 182358.

Read the full public report in the cloud browser, including vendor summary, fix confirmation, award and disclosure timeline; corroborated award with the vendor retrospective. Reviewed currency guidance separately.

  • No independent confirmation of cash settlement.
  • Currency uses later platform-wide guidance, not an explicit currency code in the historical award event.
  • Summary uses November 28 without timezone; the report and fix events display November 29 UTC.
  • No patch implementation is disclosed.

Recorded timeline

Published
2016-11-30explicit · Detailed report became public at the recorded disclosure event; later 2017 retrospective is not original publication.
Public Disclosure
2016-11-30explicit
Reported
2016-11-29explicit
Awarded
2016-11-30explicit
Fixed
2016-11-29explicit · Vendor fix-release comment at 04:36 UTC; researcher confirmation at 05:02 UTC. Summary says November 28 without a timezone; UTC timeline supplies the recorded date.

Sources and provenance

  1. Internal attachments can be exported via "Export as .zip" feature HackerOne and japz · reviewed 2026-10-03
  2. Celebrating $20M in Bounties with a Recap of Our Top 20 Up Voted Reports on Hacktivity johnk / HackerOne · reviewed 2026-10-03
  3. Vulnerability Disclosure Guidelines HackerOne · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software