Responsible Disclosure
Vulnerability Research
Selected public and disclosure-safe outcomes from vulnerability research across open-source projects and coordinated disclosure programs. Unpublished technical details remain withheld while remediation and advisory work is in progress.
Research Summary
- Submitted reports
- 92
- Vendor-confirmed outcomes
- 13
- CVE identifiers
- 5
- Products / workspaces
- 40
Report activity recorded from March 22 through August 13, 2026.
Selected Vulnerability Research
Representative outcomes limited to public or approved status-level information.
CVE-2026-59210 · Dify
Vendor-confirmed authorization boundary vulnerability
Reported May 26, 2026. Accepted with a vendor-confirmed code fix. On September 2, release-lineage review and focused regression testing confirmed that the fix shipped in 1.16.0 and remains in 1.17.0; advisory and CVE publication remain pending.
CVE-2026-57590 · Apache DolphinScheduler
Vendor-confirmed authorization boundary vulnerability
Reported June 29, 2026. Vendor-confirmed with reporter credit; remediation details, fixed-release metadata, and advisory publication remain pending.
CVE-2026-66082 · Apache DolphinScheduler
Vendor-confirmed authorization boundary vulnerability
Reported June 29, 2026. Vendor-confirmed with reporter credit; remediation details, fixed-release metadata, and advisory publication remain pending.
CVE-2026-82872 · ToolJet
Vendor-confirmed authorization boundary vulnerability
Reported June 30, 2026. Accepted and published August 7 with Finder credit. ToolJet shipped the source-verified remediation in v3.20.207-lts on August 4; the preceding v3.20.206-lts lacks the organization-binding guard added in that release. Patched-release runtime verification has not been repeated. VulnCheck published CVE-2026-82872 on August 31, preserving Finder credit and rating it High 7.1 under CVSS 4.0; the vendor advisory's original Moderate 6.8 rating remains public.
CVE pending · ToolJet
Vendor-accepted security report
Reported June 30, 2026. Accepted September 2, 2026, with reporter credit. The advisory remains private; remediation, fixed-release metadata, CVE assignment, public severity, and advisory publication remain pending.
CVE pending · Grafana
Vendor-accepted authorization boundary vulnerability
Reported March 22, 2026. Accepted August 26, 2026, with a vendor-final Medium 4.3 rating and a $656 bounty; CVE, remediation, and advisory coordination remain pending.
CVE pending · authentik
Vendor-validated security report
Reported July 29, 2026. On August 28, the maintainer confirmed the report valid and consolidated the original report into a canonical draft advisory. Patched releases are identified and reporter credit was accepted; fix verification, CVE assignment for the canonical advisory, advisory publication, and public attribution remain pending.
CVE-2026-84677 · Jenkins
Stored XSS vulnerability in update-center2
Reported August 12, 2026. Jenkins published CVE-2026-84677 in its September 2 security advisory. The issue affects update-center2 3.18.3 and earlier; version 3.18.4 escapes the plugin-provided values when rendering plugin download index pages. Jenkins rates the vulnerability Medium 5.4 and credits Yeonoh Park, SeoulTech CIS Lab (@owen050724), as the reporter.
Other Coordinated Outcomes
Five additional reports were validated in local, self-hosted environments and accepted or otherwise confirmed by their vendors. Three have numeric reported or vendor-confirmed scores, one has a vendor-rated Moderate severity without a numeric score, and one awaits a final vendor rating. Product and technical details remain private during coordinated remediation and publication.
- High 7.1
- Medium 6.1
- Medium 5.7
- Moderate Score not published
- Vendor rating Pending
Disclosure Timeline
Selected safely identifiable milestones from 2026, shown in reverse chronological order.
-
Advisory published
Jenkins
CVE-2026-84677 · Released in 3.18.4 · Medium 5.4
-
Vendor accepted
ToolJet
CVE, remediation, and advisory publication pending
-
Fix release verified
Dify
CVE-2026-59210 · Shipped since 1.16.0 · Advisory pending
-
CVE published
ToolJet
CVE-2026-82872 · High 7.1 (CVSS 4.0) · Finder credit
-
Vendor validated
authentik
Canonical advisory CVE pending · Original report consolidated
-
Accepted
Grafana
CVE pending · Medium 4.3 · $656 bounty
-
Advisory published
ToolJet
GHSA-2jhv-482p-4php · Moderate 6.8
-
Fix released
ToolJet
v3.20.207-lts · Remediation source-verified
-
Report submitted
Apache DolphinScheduler
CVE-2026-57590 · Current status: Vendor confirmed
-
Report submitted
Apache DolphinScheduler
CVE-2026-66082 · Current status: Vendor confirmed
-
Report submitted
Dify
CVE-2026-59210 · Current status: Accepted · Shipped since 1.16.0
Programs & Research Coverage
- Programs
- OSS projects, GitHub Security Advisories, ASF Security, Jenkins Security Jira, Intigriti, HackerOne, and Wordfence
- Research focus
- Authorization boundaries, tenant isolation, credential handling, workflow execution, plugin surfaces, and API surfaces