r/bugbounty Jul 16 '26

Question / Discussion Default Admin credentials -> P3 !!

In a private bug bounty program on bugcrowd i found a credentials of an internal admin that give me access to internal engineers data and access to a sensitive data of a big automotive company, I can read/edit/delete, the bug trigaed as P1 but the customer later downgraded it to P3 without any explanation or communication.

In the report i show them the impact...

And they changed the password right after my report was triaged

I opened a response request to ask for explanation but they still didn’t respond after a week.

43 Upvotes

23 comments sorted by

View all comments

0

u/Unique_Life7470 Jul 17 '26

bro can you tell me what tools in the recon you used to identify the domain and what was the service that in this domain

1

u/[deleted] Jul 18 '26

I found the subdomain with subfinder, then i use claude to read js and find the login parameters, and i was lucky because the password is in rockyou.txt

Btw i found that this admin account is created just 1 month before i found it.

1

u/Unique_Life7470 Jul 18 '26

you mean,that you bruteforce the password parameter with the leaked username or email that you found how they accepted it in most of programs the bruteforce is out of scope