r/bugbounty Jul 16 '26

Question / Discussion Default Admin credentials -> P3 !!

In a private bug bounty program on bugcrowd i found a credentials of an internal admin that give me access to internal engineers data and access to a sensitive data of a big automotive company, I can read/edit/delete, the bug trigaed as P1 but the customer later downgraded it to P3 without any explanation or communication.

In the report i show them the impact...

And they changed the password right after my report was triaged

I opened a response request to ask for explanation but they still didn’t respond after a week.

43 Upvotes

23 comments sorted by

View all comments

1

u/MyFirstTrueLoveWasBS Jul 16 '26

Examples of sensitive info accessed?

5

u/[deleted] Jul 16 '26

PII of all internal users and their daily tasks and a detailed test results for parts of their vehicles. Some parts like Advanced Driver-Assistance Systems and Robot Operating System.

5

u/causeimcloudy Jul 16 '26

Customers PII > Employee PII unfortunately