Findings and credits
- Concrete CMS
- MariaDB
- Nuxt (Vercel)
- Kiwi.com
- DuckDuckGo
- Coinbase
- bbPress
- BuddyPress
- Nitro
By the numbers
- CVEs credited
- 15
- Programs with accepted findings
- 9
- Merged upstream fix
- 1
Counted from the findings below. Every CVE links to its record on cve.org.

Findings
What I found, and what happened next.
- MariaDBMDEV-39762HackerOneReported 2026-05-26Medium 4.1Found
Replica crash from a malformed compressed replication event
Memory safety (32-bit size truncation into a fixed stack buffer)
ImpactCrashes the replica. Needs a malicious or compromised primary, or a tampered replication stream.
OutcomeFixed in MariaDB 10.11.19, 11.4.13, 11.8.9 and 12.3.3 (released 2026-08-24), and 13.0.2 (2026-09-15).
The HackerOne report is private. The public MariaDB ticket says “Reported by Winston Crooker”.
- Vercel Open Source (Nuxt)HackerOneReported 2026-05-09Medium 6.9Found
Other local users could read a developer's project source through the Nuxt dev server's IPC socket
Exposure of resource to wrong sphere (local, cross-user)
ImpactOn a shared Linux machine, another user could read source files and .env values while
nuxt devwas running.OutcomeFixed in nuxt 4.4.7 and 3.21.7. Resolved 2026-06-16.
Bounty paid by Vercel Open Source on HackerOne. The public advisory credits other reporters; my report was filed May 9, before the advisory was published on June 2.
- Concrete CMSCVE-2026-8204HackerOnePublished 2026-05-21Medium 6.3Found
A public calendar block could be used to read private calendar data
Authorization bypass
ImpactPrivate calendar events readable through a public page.
OutcomeFixed in Concrete CMS 9.5.1.
- Concrete CMSCVE-2026-8236HackerOnePublished 2026-05-21Medium 6.3Found
File usage endpoint had no authentication check
IDOR, missing authentication
ImpactAnyone could pull page IDs, versions and URL paths by file ID, no login needed.
OutcomeFixed in Concrete CMS 9.5.1.
- Concrete CMSCVE-2026-8240HackerOnePublished 2026-05-21Medium 6.3Found
Unauthenticated page metadata leak that revealed private, draft and restricted pages
Information disclosure
ImpactPrivate and draft pages, with their titles, paths and authors, discoverable without logging in.
OutcomeFixed in Concrete CMS 9.5.1.
- Kiwi.comHackerOneReported 2026-05-02LowFound
Cross-tenant Vault secret exposure in k8s-vault-operator
ImpactLow (program-rated)
OutcomeFixed in k8s-vault-operator v1.6.2. $200 bounty.
- DuckDuckGoHackerOneReported 2026-04-05LowFound
Lookalike localhost hostnames could switch off the Privacy Extension's protections
ImpactLow
OutcomeFixed in DuckDuckGo Privacy Extension 2026.5.22.
- CoinbaseHackerOneResolved 2026-09-15Medium 4.1Found
AgentKit x402: the signed payment ignores the maxPaymentUsdc cap and is under-reported
ImpactMedium
Outcome$200 bounty.
Full CVE log
15 CVEs, each linked to its record on cve.org. Scores are the program's own CVSS 4.0 ratings.
| CVE | Title | Class | Severity | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-8204 | A public calendar block could be used to read private calendar data | Authorization bypass | Medium 6.3 | 9.5.1 | 2026-05-21 |
| CVE-2026-8236 | File usage endpoint had no authentication check | IDOR, missing authentication | Medium 6.3 | 9.5.1 | 2026-05-21 |
| CVE-2026-8240 | Unauthenticated page metadata leak that revealed private, draft and restricted pages | Information disclosure | Medium 6.3 | 9.5.1 | 2026-05-21 |
| CVE-2026-81908 | REST API groups list skipped per-group permission checks | Missing authorization | Medium 6.0 | 9.5.3 | 2026-09-11 |
| CVE-2026-68527 | Calendar event editor checked the wrong calendar, so users could read and overwrite events they had no access to | Authorization bypass (IDOR) | Medium 5.9 | 9.5.3 | 2026-09-10 |
| CVE-2026-68526 | Calendar event duplicate accepted forged cross-site requests | CSRF | Medium 5.3 | 9.5.3 | 2026-09-11 |
| CVE-2026-84432 | Boards custom slot dialog accepted forged cross-site requests | CSRF | Medium 5.3 | 9.5.3 | 2026-09-10 |
| CVE-2026-8340 | Forged requests could switch a file to an older or unpublished version | CSRF | Low 2.3 | 9.5.1 | 2026-05-22 |
| CVE-2026-8347 | Users with view-only access could reorder another entity's Express associations | IDOR | Low 2.3 | 9.5.1 | 2026-05-22 |
| CVE-2026-87031 | REST API user creation had no permission check | Missing authorization | Low 2.1 | 9.5.4 | 2026-09-16 |
| CVE-2026-18421 | Board editors could change or delete other boards' data sources | Missing authorization | Low 2.1 | 9.5.3 | 2026-09-15 |
| CVE-2026-68529 | Express advanced search returned entries from entities the user could not view | Missing authorization | Low 2.1 | 9.5.3 | 2026-09-15 |
| CVE-2026-68530 | Board instance actions skipped the parent board's permission check | Missing authorization | Low 2.1 | 9.5.3 | 2026-09-15 |
| CVE-2026-18422 | Multilingual page assign had no destination check and no CSRF token | Missing authorization, CSRF | Low 2.1 | 9.5.3 | 2026-09-15 |
| CVE-2026-18425 | Sitemap reorder ignored per-page edit permission and had no CSRF token | Missing authorization, CSRF | Low 2.1 | 9.5.3 | 2026-09-15 |
Credits and merged fix
- bbPress 2.6.17Credited contributorSecurity and maintenance release, 2026-09-16. Named in the release's contributor thank-you.codex.bbpress.org/releases/bbpress-2-6-17
- BuddyPress 14.5.2Credited contributorSecurity release, 2026-07-29. Listed among the release contributors.codex.buddypress.org/releases/version-14-5-2
- NitroMerged upstream fixRestricted the dev server's task runner endpoints to local requests. Merged 2026-06-29.github.com/nitrojs/nitro/pull/4389
More on HackerOne
I also have accepted reports at Netflix, Spotify and Elastic, a confidential program, and more at Vercel Open Source. These are private, so the details stay on my HackerOne profile.

“Thanks Winston Crooker for reporting.”

How I work
I bring the ideas. The AI does the digging.
I work by direction. I pick the targets, form the idea of where a weakness might be and how to reach it, and tell the AI how I want it pursued. It does the heavy lifting: reading the code, chasing the lead, building the proof. I read what comes back, decide what holds up, and stand behind every report I send.
Standing rules
- A finding only counts when the exploit runs end to end, with unauthorized data in the response or confirmation on the victim's side.
- A different error message, a different status code, or a missing check in the source is never proof by itself. The exploit has to actually succeed.
- Before I report anything, I have the AI read the target's security documentation, so I can rule out behavior that is documented as unsafe by design or left to the developer.
- Every report gets an adversarial review pass, with the AI playing a skeptical triager, before I submit it.
AI-assisted reports have a bad reputation with triagers. These rules are how I keep mine out of that pile.

Writeups
Notes from the public record.
CVE-2026-68527
The calendar editor checked the wrong calendar
Concrete CMS lets a user change a calendar event through an edit dialog. In versions 8.3.0 through 9.5.2, that dialog decided whether to allow the change by checking the calendar ID sent in the request, not the calendar that actually owns the event. So a user with the "Add Event" permission on one calendar could open events on calendars they had no access to, read them, and overwrite them. They could also delete an event's original local occurrence.
There was a limit. Publishing the changed version to the live calendar, which demotes the previously approved version, also needed approval rights for calendar events or a workflow that approves changes automatically.
I reported it to the Concrete CMS security team. They rated it 5.9 under CVSS 4.0, and the fix shipped in 9.5.3. The CVE record has the full description.
cve.org/CVERecord?id=CVE-2026-68527Concrete CMS 9.5.3 release notes
CVE-2026-8240
Private page details, readable without logging in
In Concrete CMS 9.5.0 and below, a backend component named in the CVE title as Backend\SummaryTemplate returned page metadata to visitors who were not logged in. It did this for every page with a summary template configured, including pages that were private, still in draft, or restricted.
For each of those pages, an anonymous visitor could confirm that the page existed and read its title, path, description and author. The record lists exactly those four fields, so this was a metadata leak, but it covered every page that had a summary template, whatever its permissions said.
I reported it to the Concrete CMS security team. They rated it 6.3 under CVSS 4.0: reachable over the network, with no login and no user interaction, and a low confidentiality impact. The fix shipped in 9.5.1, and the CVE record names me as the reporter.
cve.org/CVERecord?id=CVE-2026-8240Concrete CMS 9.5.1 release notes
CVE-2026-81908
A permission check that always said yes
The Concrete CMS REST API lists groups at GET /ccm/api/1.0/groups. In versions 9.2.0 through 9.5.2, the method behind that endpoint, listGroups() in Groups.php, registered a permission checker callback that returned true no matter what. The view permissions on individual groups never applied to the list.
Any authenticated user whose API token carried the groups:read scope could call the endpoint and get back every group on the site, including groups they had no permission to view. The CVE record describes what that exposes as the organization's group structure, roles, and access hierarchy.
I reported it to the Concrete CMS security team. They rated it 6.0 under CVSS 4.0, with a high confidentiality impact and a low privilege requirement, and the fix shipped in 9.5.3.
cve.org/CVERecord?id=CVE-2026-81908Concrete CMS 9.5.3 release notes
MDEV-39762
A size check that wrapped around
MariaDB replicas can receive compressed query events from their primary. To uncompress one, the replica reads a 32-bit length from the event header, works with it as a 64-bit value, and then casts the result back to 32 bits to decide where the data goes. Small results go into a fixed 4 KB buffer on the stack. Larger ones get a heap allocation.
If the length in the header is close to the 32-bit maximum, the cast wraps it around to a small number. The replica then picks the stack buffer for data far larger than 4 KB, and its IO thread crashes.
A normal primary cannot produce an event like that, so this needs a malicious or compromised primary, or a tampered replication stream. The ticket includes a test that reproduces the crash on a debug build. MariaDB fixed it in 10.11.19, 11.4.13, 11.8.9 and 12.3.3, released August 24, 2026, and in 13.0.2.

