Root cause
The vendor attributes the issue to a support-system misconfiguration that allowed support workflows to cross the boundary into internal documentation. The public summary does not reveal the precise configuration, authentication prerequisites or permission-propagation mechanism; an identity-entitlement failure is a defensive interpretation, not a documented implementation detail.
Demonstrated impact
The vendor confirms access to nonpublic internal documentation and the ability to view and modify limited Confluence content. It does not establish unrestricted administrative control, the volume of material exposed, or broader compromise. The timeline records accepted retesting and Resolved status on June 3, 2025; redacted comment bodies do not reveal the corrective configuration or exact deployment date.
Lessons for review
- Editorial lesson: assess whether external support workflows can confer access to employee-only documentation.
- Editorial lesson: review integration permissions separately for read and write access; limited modification is distinct from unrestricted control.
- Editorial lesson: verify the corrected access boundary after configuration changes without treating a resolution status as evidence of the precise fix.
Award and evidence
Dollar notation appears in the report UI; USD denomination is contextual from HackerOne’s disclosure policy. Award events do not establish cash receipt. One-report total: USD 5,000 to red_darkin and USD 7,500 to madara_; neither recipient individually received USD 10,000.
Freshly read the public vendor summary, expanded award events, accepted-retest and resolution events in the cloud browser. Technical and comment bodies remain redacted. Existing currency evidence retained without a fresh review; no target testing.
- Award events establish an award, not independently audited settlement.
- Exact fix-deployment date is unavailable; a Resolved status date is not treated as deployment.
- Technical report and comment bodies are redacted; interpretation is limited to the vendor’s public summary and event metadata.
- Exact access prerequisites and the corrective configuration are not disclosed; no specific identity provisioning or entitlement mechanism is established by the public summary.
Recorded timeline
- Published
- 2025-08inferred · Disclosure events appear August 13 and August 15, 2025. The sidebar shows August 15; month retained because first public day is ambiguous.
- Public Disclosure
- 2025-08inferred · Disclosure events appear August 13 and August 15, 2025. The sidebar shows August 15; month retained because first public day is ambiguous.
- Reported
- 2025-04-26explicit
- Awarded
- 2025-05-30explicit
Sources and provenance
- Support integration exposed internal Confluence documentation (report 3113398) HackerOne and the credited researchers · reviewed 2026-10-03
- Vulnerability Disclosure Standards: Bug Bounty payment denomination HackerOne · reviewed 2026-10-02
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.