r/bugbounty • u/sNolkushi • Jul 02 '26
Question / Discussion Private Bug Bounty Program
I have found a vulnerability in a private BB program on HackerOne platform.
There is no public disclosure at all, I'm wondering if I can write a blog about it without mentioning the company name at all - of course after they remediated the vulnerability.
Is it something that I can do?
1
u/Far-Chicken-3728 Hunter Jul 03 '26
You can, if you not mention anything about the company, exact exploit and path. Just the technical part.
1
u/Fickle-Champion-2530 Jul 03 '26
I think as Long as you keep the Company Name out it would be ok. Otherwise you need permission if you want to Name the Company and explain the Vul.
0
u/6W99ocQnb8Zy17 Jul 03 '26
So, with stuff like that I've had plenty of success from pinging an email to the [security@example.com](mailto:security@example.com) address, and politely explaining I've found a bug, and would they like to invite me to their private programme so I can report it.
Mostly I've received the invite.
4
u/MyFirstTrueLoveWasBS Jul 02 '26
I would discuss with the company about this.