vulns.co
/
GKData.io MCP

AZAuthorization and tenant boundaries · 2 min read

Shopify automatic account conversion lost merchant-consent binding

Shopify confirms a $20,000 award for unauthorized collaborator access caused by automatic account conversion.

Read the primary source AZAuthorization and tenant boundariesReviewed 2026-10-03

Root cause

Account-conversion logic did not preserve the distinction between identity linkage and authorization to collaborate on a merchant’s store. The vendor attributes the issue to automatic conversion of ordinary accounts into collaborator accounts.

Demonstrated impact

The vendor confirms unintended store access without merchant interaction in a partner-account context, and says it fixed the issue within hours. Its retrospective does not establish data extraction, the exact permissions obtained or the researcher’s discovery process.

Lessons for review

  • Editorial lesson: require an independently verified entitlement for each role transition; matching identity attributes do not prove resource access rights.
  • Editorial lesson: preserve merchant approval when accounts are linked, merged or automatically converted.
  • Editorial lesson: model authorization before and after lifecycle transitions, including repeated or conflicting identities, using approved test accounts.

Award and evidence

USD 20,000Bug Bounty · Vendor Confirmed

One report, separate from event totals. USD is a contextual inference from HackerOne’s 2026 platform policy, nine years after the 2017 award; that policy does not prove settlement.

Read public primary-source text and checked award scope, provenance and dates. No target testing.

  • The underlying linked HackerOne report was JavaScript-only in text retrieval and was not independently reviewed.
  • Currency context is platform-wide and later than the award; no independent payment audit is claimed.
  • No exact reporting, fix or payment date was established.

Recorded timeline

Published
2018-02-22explicit
Awarded
2017explicit · The vendor identifies the award as occurring during 2017; no precise day is supplied.

Sources and provenance

  1. 2017 Bug Bounty Year in Review Peter Yaworski / Shopify · reviewed 2026-10-03
  2. Vulnerability Disclosure Standards HackerOne · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software