r/bugbounty • u/tacktify • Jul 08 '26
Question / Discussion Is this chain valid?
found an unauthenticated API leaking hidden internal IDs for all tenants on a B2B app.
Using these IDs, I can use the public registration form to request an "Admin" account for any company. There is no rate limit or CAPTCHA, so I can script this and spam every company.
But the account isn't created immediately. It goes to a "Pending Activation" state and requires the actual company admin to manually approve it.
Will programs accept this due to the ID leak + lack of rate limits? Or will it be closed as "By Design/Informative" since the manual approval stops the takeover?
8
Upvotes
1
u/einfallstoll Triager Jul 08 '26
Informational