vulns.co
/
GKData.io MCP

AZAuthorization and tenant boundaries · 2 min read

Support integration exposed internal Confluence documentation

A support-system misconfiguration allowed external access to internal Confluence documentation, including limited content modification. One report received USD 12,500 split between two researchers.

Read the primary source AZAuthorization and tenant boundariesReviewed 2026-10-03

Root cause

The vendor attributes the issue to a support-system misconfiguration that allowed support workflows to cross the boundary into internal documentation. The public summary does not reveal the precise configuration, authentication prerequisites or permission-propagation mechanism; an identity-entitlement failure is a defensive interpretation, not a documented implementation detail.

Demonstrated impact

The vendor confirms access to nonpublic internal documentation and the ability to view and modify limited Confluence content. It does not establish unrestricted administrative control, the volume of material exposed, or broader compromise. The timeline records accepted retesting and Resolved status on June 3, 2025; redacted comment bodies do not reveal the corrective configuration or exact deployment date.

Lessons for review

  • Editorial lesson: assess whether external support workflows can confer access to employee-only documentation.
  • Editorial lesson: review integration permissions separately for read and write access; limited modification is distinct from unrestricted control.
  • Editorial lesson: verify the corrected access boundary after configuration changes without treating a resolution status as evidence of the precise fix.

Award and evidence

USD 12,500Bug Bounty · Vendor Confirmed

Dollar notation appears in the report UI; USD denomination is contextual from HackerOne’s disclosure policy. Award events do not establish cash receipt. One-report total: USD 5,000 to red_darkin and USD 7,500 to madara_; neither recipient individually received USD 10,000.

Freshly read the public vendor summary, expanded award events, accepted-retest and resolution events in the cloud browser. Technical and comment bodies remain redacted. Existing currency evidence retained without a fresh review; no target testing.

  • Award events establish an award, not independently audited settlement.
  • Exact fix-deployment date is unavailable; a Resolved status date is not treated as deployment.
  • Technical report and comment bodies are redacted; interpretation is limited to the vendor’s public summary and event metadata.
  • Exact access prerequisites and the corrective configuration are not disclosed; no specific identity provisioning or entitlement mechanism is established by the public summary.

Recorded timeline

Published
2025-08inferred · Disclosure events appear August 13 and August 15, 2025. The sidebar shows August 15; month retained because first public day is ambiguous.
Public Disclosure
2025-08inferred · Disclosure events appear August 13 and August 15, 2025. The sidebar shows August 15; month retained because first public day is ambiguous.
Reported
2025-04-26explicit
Awarded
2025-05-30explicit

Sources and provenance

  1. Support integration exposed internal Confluence documentation (report 3113398) HackerOne and the credited researchers · reviewed 2026-10-03
  2. Vulnerability Disclosure Standards: Bug Bounty payment denomination HackerOne · reviewed 2026-10-02

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software