vulns.co
/
GKData.io MCP

AZAuthorization and tenant boundaries · 2 min read

GraphQL object authorization exposed private-program metadata

HackerOne awarded USD 25,000 in 2022 for private-program GraphQL metadata exposure; the report became public in January 2025 (primary).

Read the primary source AZAuthorization and tenant boundariesReviewed 2026-10-03

Root cause

A GraphQL object lookup failed to preserve private-program visibility for associated metadata (primary). The researcher described an unauthenticated request and triage validated the report. Exposure depended on resolving a valid program-associated object; the public record does not establish equal reachability across every private-program type. Conceptually, resolving an object is distinct from authorizing its disclosure. The exact omitted check and code-level repair are not public.

Demonstrated impact

The researcher demonstrated private-program metadata exposure. HackerOne’s internal investigation additionally determined that report titles could be accessed and raised severity to critical; title access was a vendor-assessed consequence, not the researcher’s demonstrated result in the visible evidence. HackerOne said it found no exploitation beyond the demonstration (primary). Full report-body access is not established.

Lessons for review

  • Editorial design lesson: independently enforce visibility on object lookup, returned fields and related objects, including unauthenticated access paths.
  • Editorial privacy lesson: program metadata and report titles can disclose confidential information even when report bodies remain protected.
  • HackerOne marked the report Resolved on July 5, 2022 (primary). Treat that as resolution evidence; the deployment date and implementation-level remediation remain unknown.

Award and evidence

USD 25,000Bug Bounty · Vendor Confirmed

One report award, not verified cash receipt. USD is contextual from HackerOne’s platform-wide payment policy reviewed in October 2026, more than four years after the July 2022 award; it does not independently establish that payment’s denomination or settlement.

Freshly read the rendered public report, researcher demonstration, vendor triage/investigation statements and award/disclosure events in the cloud browser; independently read platform currency policy. Omitted payloads and private-program details.

  • Award events establish an award, not independently audited settlement; later platform-wide currency policy is contextual evidence.
  • Exact fix-deployment date is unavailable; Resolved status is not treated as deployment.
  • Code-level patch details are not public. Vendor investigation supports possible report-title access; the visible researcher evidence demonstrates metadata exposure.
  • The researcher expressed uncertainty about coverage of fully private programs. The record does not generalize exposure to every private-program category.
  • Updated comment timestamps differ from original event dates.

Recorded timeline

Published
2025-01-21explicit · Public disclosure event activity-32092519; the underlying report and award are from 2022.
Public Disclosure
2025-01-21explicit
Reported
2022-06-28explicit
Awarded
2022-07-05explicit

Sources and provenance

  1. GraphQL object authorization exposed private-program metadata (report 1618347) HackerOne and the credited researchers · reviewed 2026-10-03
  2. Vulnerability Disclosure Standards: Bug Bounty payment denomination HackerOne · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software