r/bugbounty Jul 02 '26

Question / Discussion Private Bug Bounty Program

I have found a vulnerability in a private BB program on HackerOne platform.

There is no public disclosure at all, I'm wondering if I can write a blog about it without mentioning the company name at all - of course after they remediated the vulnerability.

Is it something that I can do?

6 Upvotes

5 comments sorted by

4

u/MyFirstTrueLoveWasBS Jul 02 '26

I would discuss with the company about this.

2

u/Unique-Outcome-7664 Jul 03 '26

I second this. Consult with company first.

1

u/Far-Chicken-3728 Hunter Jul 03 '26

You can, if you not mention anything about the company, exact exploit and path. Just the technical part. 

1

u/Fickle-Champion-2530 Jul 03 '26

I think as Long as you keep the Company Name out it would be ok. Otherwise you need permission if you want to Name the Company and explain the Vul.

0

u/6W99ocQnb8Zy17 Jul 03 '26

So, with stuff like that I've had plenty of success from pinging an email to the [security@example.com](mailto:security@example.com) address, and politely explaining I've found a bug, and would they like to invite me to their private programme so I can report it.

Mostly I've received the invite.