Root cause
A GraphQL object lookup failed to preserve private-program visibility for associated metadata (primary). The researcher described an unauthenticated request and triage validated the report. Exposure depended on resolving a valid program-associated object; the public record does not establish equal reachability across every private-program type. Conceptually, resolving an object is distinct from authorizing its disclosure. The exact omitted check and code-level repair are not public.
Demonstrated impact
The researcher demonstrated private-program metadata exposure. HackerOne’s internal investigation additionally determined that report titles could be accessed and raised severity to critical; title access was a vendor-assessed consequence, not the researcher’s demonstrated result in the visible evidence. HackerOne said it found no exploitation beyond the demonstration (primary). Full report-body access is not established.
Lessons for review
- Editorial design lesson: independently enforce visibility on object lookup, returned fields and related objects, including unauthenticated access paths.
- Editorial privacy lesson: program metadata and report titles can disclose confidential information even when report bodies remain protected.
- HackerOne marked the report Resolved on July 5, 2022 (primary). Treat that as resolution evidence; the deployment date and implementation-level remediation remain unknown.
Award and evidence
One report award, not verified cash receipt. USD is contextual from HackerOne’s platform-wide payment policy reviewed in October 2026, more than four years after the July 2022 award; it does not independently establish that payment’s denomination or settlement.
Freshly read the rendered public report, researcher demonstration, vendor triage/investigation statements and award/disclosure events in the cloud browser; independently read platform currency policy. Omitted payloads and private-program details.
- Award events establish an award, not independently audited settlement; later platform-wide currency policy is contextual evidence.
- Exact fix-deployment date is unavailable; Resolved status is not treated as deployment.
- Code-level patch details are not public. Vendor investigation supports possible report-title access; the visible researcher evidence demonstrates metadata exposure.
- The researcher expressed uncertainty about coverage of fully private programs. The record does not generalize exposure to every private-program category.
- Updated comment timestamps differ from original event dates.
Recorded timeline
- Published
- 2025-01-21explicit · Public disclosure event activity-32092519; the underlying report and award are from 2022.
- Public Disclosure
- 2025-01-21explicit
- Reported
- 2022-06-28explicit
- Awarded
- 2022-07-05explicit
Sources and provenance
- GraphQL object authorization exposed private-program metadata (report 1618347) HackerOne and the credited researchers · reviewed 2026-10-03
- Vulnerability Disclosure Standards: Bug Bounty payment denomination HackerOne · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.