Yeonoh Park

Responsible Disclosure

Vulnerability Research

Selected public and disclosure-safe outcomes from vulnerability research across open-source projects and coordinated disclosure programs. Unpublished technical details remain withheld while remediation and advisory work is in progress.

Research Summary

Submitted reports
92
Vendor-confirmed outcomes
13
CVE identifiers
5
Products / workspaces
40

Report activity recorded from March 22 through August 13, 2026.

Selected Vulnerability Research

Representative outcomes limited to public or approved status-level information.

CVE-2026-59210 · Dify

Vendor-confirmed authorization boundary vulnerability

Reported May 26, 2026. Accepted with a vendor-confirmed code fix. On September 2, release-lineage review and focused regression testing confirmed that the fix shipped in 1.16.0 and remains in 1.17.0; advisory and CVE publication remain pending.

CVE-2026-57590 · Apache DolphinScheduler

Vendor-confirmed authorization boundary vulnerability

Reported June 29, 2026. Vendor-confirmed with reporter credit; remediation details, fixed-release metadata, and advisory publication remain pending.

CVE-2026-66082 · Apache DolphinScheduler

Vendor-confirmed authorization boundary vulnerability

Reported June 29, 2026. Vendor-confirmed with reporter credit; remediation details, fixed-release metadata, and advisory publication remain pending.

CVE-2026-82872 · ToolJet

Vendor-confirmed authorization boundary vulnerability

Reported June 30, 2026. Accepted and published August 7 with Finder credit. ToolJet shipped the source-verified remediation in v3.20.207-lts on August 4; the preceding v3.20.206-lts lacks the organization-binding guard added in that release. Patched-release runtime verification has not been repeated. VulnCheck published CVE-2026-82872 on August 31, preserving Finder credit and rating it High 7.1 under CVSS 4.0; the vendor advisory's original Moderate 6.8 rating remains public.

CVE pending · ToolJet

Vendor-accepted security report

Reported June 30, 2026. Accepted September 2, 2026, with reporter credit. The advisory remains private; remediation, fixed-release metadata, CVE assignment, public severity, and advisory publication remain pending.

CVE pending · Grafana

Vendor-accepted authorization boundary vulnerability

Reported March 22, 2026. Accepted August 26, 2026, with a vendor-final Medium 4.3 rating and a $656 bounty; CVE, remediation, and advisory coordination remain pending.

CVE pending · authentik

Vendor-validated security report

Reported July 29, 2026. On August 28, the maintainer confirmed the report valid and consolidated the original report into a canonical draft advisory. Patched releases are identified and reporter credit was accepted; fix verification, CVE assignment for the canonical advisory, advisory publication, and public attribution remain pending.

CVE-2026-84677 · Jenkins

Stored XSS vulnerability in update-center2

Reported August 12, 2026. Jenkins published CVE-2026-84677 in its September 2 security advisory. The issue affects update-center2 3.18.3 and earlier; version 3.18.4 escapes the plugin-provided values when rendering plugin download index pages. Jenkins rates the vulnerability Medium 5.4 and credits Yeonoh Park, SeoulTech CIS Lab (@owen050724), as the reporter.

Other Coordinated Outcomes

Five additional reports were validated in local, self-hosted environments and accepted or otherwise confirmed by their vendors. Three have numeric reported or vendor-confirmed scores, one has a vendor-rated Moderate severity without a numeric score, and one awaits a final vendor rating. Product and technical details remain private during coordinated remediation and publication.

  • High 7.1
  • Medium 6.1
  • Medium 5.7
  • Moderate Score not published
  • Vendor rating Pending

Disclosure Timeline

Selected safely identifiable milestones from 2026, shown in reverse chronological order.

  1. Advisory published

    Jenkins

    CVE-2026-84677 · Released in 3.18.4 · Medium 5.4

  2. Vendor accepted

    ToolJet

    CVE, remediation, and advisory publication pending

  3. Fix release verified

    Dify

    CVE-2026-59210 · Shipped since 1.16.0 · Advisory pending

  4. CVE published

    ToolJet

    CVE-2026-82872 · High 7.1 (CVSS 4.0) · Finder credit

  5. Vendor validated

    authentik

    Canonical advisory CVE pending · Original report consolidated

  6. Accepted

    Grafana

    CVE pending · Medium 4.3 · $656 bounty

  7. Advisory published

    ToolJet

    GHSA-2jhv-482p-4php · Moderate 6.8

  8. Fix released

    ToolJet

    v3.20.207-lts · Remediation source-verified

  9. Report submitted

    Apache DolphinScheduler

    CVE-2026-57590 · Current status: Vendor confirmed

  10. Report submitted

    Apache DolphinScheduler

    CVE-2026-66082 · Current status: Vendor confirmed

  11. Report submitted

    Dify

    CVE-2026-59210 · Current status: Accepted · Shipped since 1.16.0

Programs & Research Coverage

Programs
OSS projects, GitHub Security Advisories, ASF Security, Jenkins Security Jira, Intigriti, HackerOne, and Wordfence
Research focus
Authorization boundaries, tenant isolation, credential handling, workflow execution, plugin surfaces, and API surfaces