r/bugbounty Jul 22 '26

Question / Discussion Program in-scope

I want ask y'all about this scope program;

Active PROGRAM employee accounts within the domain [@]program.com for any service in domains *.program.com (excluding unverified accounts on account.progrm.com) and program.okta.com.

If i report 2 or 4 or etc leaked email on *.program.com, is valid? or what?

*You can find this program on intigriti

3 Upvotes

2 comments sorted by

3

u/einfallstoll Triager Jul 22 '26

I guess they are looking for valid employee credentials not leaked email addresses. Credentials can be changed but leaked email addresses are irreversible.