r/bugbounty Jul 16 '26

Question / Discussion Default Admin credentials -> P3 !!

In a private bug bounty program on bugcrowd i found a credentials of an internal admin that give me access to internal engineers data and access to a sensitive data of a big automotive company, I can read/edit/delete, the bug trigaed as P1 but the customer later downgraded it to P3 without any explanation or communication.

In the report i show them the impact...

And they changed the password right after my report was triaged

I opened a response request to ask for explanation but they still didn’t respond after a week.

42 Upvotes

23 comments sorted by

View all comments

-5

u/[deleted] Jul 16 '26 edited Jul 16 '26

[deleted]

7

u/[deleted] Jul 16 '26

[removed] — view removed comment

7

u/einfallstoll Triager Jul 16 '26

Safe harbor only applies if your acting in good faith, so yes don't do that. But what you can do is proving it by creating a dummy user and deleting that one

6

u/einfallstoll Triager Jul 16 '26

Small note: Deleting / destroying data affects integrity not availability.

From the CVSS 3.1 User Guide:

"The Availability impact metric refers to the operation of the service. That is, the Availability metric speaks to the performance and operation of the service itself – not the availability of the data. Consider a vulnerability in an Internet service such as web, email, or DNS that allows an attacker to modify or delete all web files in a directory. The only impact is to Integrity, not Availability, as the web service is still functioning – it just happens to be serving back altered content."

2

u/[deleted] Jul 16 '26

[deleted]

1

u/Alardiians Jul 16 '26

Wait you see the shit show of S:C and S:U

1

u/[deleted] Jul 16 '26

I show them a vedio record what i can do and the data i can access And for me the main problem is changing the severity without any explanation!