{"id":"03997f62-b87f-48d5-92cc-7d4e0438df87","engagementId":"e2338646-fb4f-4cc2-94ed-2a13a9907c9c","data":{"brief":{"id":"fcb6adc9-48ea-48af-82ae-1d50ce9fdece","name":"Kinaxis Vulnerability Disclosure Engagement","tagline":"Powering the world's supply chains.","description":"\u003cp\u003eKinaxis is a global leader in modern supply chain management. We serve supply chains and the people who manage them. Our software is trusted by renowned global brands to provide the agility and predictability needed to navigate today’s volatility and disruption. We combine our patented concurrency technique with a human-centered approach to AI to empower businesses of all sizes to orchestrate their end-to-end supply chain network, from multi-year strategic planning through down-to-the-second execution and last-mile delivery.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Kinaxis not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Kinaxis, you can report it to this engagement. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eEngagement Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe do not accept reports that contain low-effort or AI-generated content. Submissions must demonstrate original analysis, clear understanding of the issue, and actionable detail. Reports lacking meaningful human input will be rejected\u003c/li\u003e\n\u003cli\u003ePotential post-exploitation scenarios: If you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity\u003c/li\u003e\n\u003cli\u003eYou are testing on production. Behavior that compromises the stability and integrity of the target(s) is out of scope.\n\n\u003cul\u003e\n\u003cli\u003eFor example, do not target other users' data (use one of your other sets of credentials), delete/remove/edit parts of the site, engage any sort of DoS attack, and/or compromise any target's ability to function for other users. If you believe that you have found a vulnerability of this nature, please stop further testing and report it\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eReport Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities discovered on multiple paths, endpoints, parameters will be treated as duplicates. This includes findings across different environments (e.g., development, staging, production) unless the impact or exploitation method is materially different. Please submit only one report\u003c/li\u003e\n\u003cli\u003eReports must contain the role used for testing, a clear explanation of the issue and the security impact along with detailed steps to reproduce it. If the issue cannot be reliably reproduced based on your report, it may be considered ineligible for a reward\u003c/li\u003e\n\u003cli\u003eRemediation Suggestion: While not mandatory, we encourage researchers to suggest a fix to assist our developers with remediation\u003c/li\u003e\n\u003cli\u003eDo not submit more than one vulnerability per report. In cases where demonstrating impact requires chaining multiple vulnerabilities together, those can be included in the same report as long as the linkage is clearly explained\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eAll applications within scope are publicly accessible. \u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eCredentials are not required or provided for testing. However, you may create accounts where possible using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003eTo support your testing, we’ve highlighted several key areas of interest. While we ask that you report any efforts related to these areas, please note that testing is not limited to them. Submissions outside of these focus areas are equally welcomed and appreciated.\u003c/p\u003e\n\n\u003cp\u003e\u003ccode\u003eInternal Data Exposure\u003c/code\u003e: Any publicly accessible endpoint, storage bucket, or misconfigured resource that exposes Kinaxis internal data, such as configuration files, credentials, API keys, employee records, or proprietary business data, without requiring authentication\u003c/p\u003e\n\n\u003cp\u003e\u003ccode\u003eCustomer PII Exposure\u003c/code\u003e: Any publicly reachable resource that exposes a customer’s personally identifiable information (names, emails, contract details, etc.) without requiring a login\u003c/p\u003e\n\n\u003cp\u003e\u003ccode\u003eSubdomain Takeover\u003c/code\u003e: Identification of *.kinaxis.com subdomains pointing to unclaimed third-party services (e.g., expired GitHub Pages, Azure and/or GCP endpoints) that could be hijacked by a malicious actor\u003c/p\u003e\n\n\u003cp\u003e\u003ccode\u003eSensitive File \u0026amp; Directory Exposure\u003c/code\u003e: Publicly indexed or accessible files such as .env, .git, backup, config, or database dump files hosted on Kinaxis-controlled infrastructure\u003c/p\u003e\n\n\u003cp\u003e\u003ccode\u003eUnauthenticated API Data Leakage\u003c/code\u003e: Public-facing API endpoints that return sensitive internal or customer data without requiring any form of authentication or authorization\u003c/p\u003e\n\n\u003cp\u003e\u003ccode\u003eSecurity Misconfiguration\u003c/code\u003e: Systems, applications, cloud services, or security controls improperly configured, left with default settings, or not securely maintained, exposing them to unauthorized access, data leakage, or other attacks\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cp\u003eWhen N-Day bugs are released to the public and can be exploited within our target(s), please let us know immediately. Each report will be reviewed on a case by case basis.\u003c/p\u003e\n\n\u003ch2\u003eLeaked Credentials\u003c/h2\u003e\n\n\u003cp\u003eSubmissions related to leaked or exposed employee credentials (e.g., dark web forums, credential dumps) will be reviewed on a case-by-case basis and may qualify for points-based compensation only. The use of any leaked credentials during testing is strictly prohibited and may result in disqualification from the bounty program.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eProhibited Activities\u003c/h2\u003e\n\n\u003cp\u003eThe following testing techniques are strictly prohibited on all In-Scope Assets, regardless of the target asset:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDenial of Service (DoS/DDoS): Any attack or test designed to degrade, disrupt, or overwhelm Kinaxis systems or web properties\u003c/li\u003e\n\u003cli\u003eLoad \u0026amp; Stress Testing: Any form of automated load testing, stress testing, or high-volume request generation\u003c/li\u003e\n\u003cli\u003eRate Limiting Attacks: Testing or exploiting rate limiting controls on any endpoint\u003c/li\u003e\n\u003cli\u003eSocial Engineering: Any attempt to manipulate, deceive, or phish Kinaxis employees, contractors, or customers, whether via email, phone, in person, or any other channel\u003c/li\u003e\n\u003cli\u003ePhishing: Creating or distributing fraudulent communications impersonating Kinaxis or its personnel for any purpose related to this program\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\n\n\u003cul\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting bypass attempts\u003c/li\u003e\n\u003cli\u003eEmail bombing or flooding\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eALL forms of Social Engineering\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our \u003ca href=\"https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eTerms \u0026amp; Conditions\u003c/a\u003e  that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via our \u003ca href=\"https://bugcrowd-support.freshdesk.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eFreshdesk Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"e0277c2a-0772-4b0d-ac1b-9e1d0b00f12d","name":"In Scope ","targets":[{"id":"1edd10f4-3a41-4a4e-988c-4521d95de863","uri":"","name":"*.kinaxis.com/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"083cfd3d-f0e3-48d4-bdd1-a76d84867caa","sortOrder":0},"sortOrder":0,"tags":[{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"1edd10f4-3a41-4a4e-988c-4521d95de863"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"1edd10f4-3a41-4a4e-988c-4521d95de863"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"1edd10f4-3a41-4a4e-988c-4521d95de863"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"1edd10f4-3a41-4a4e-988c-4521d95de863"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"1edd10f4-3a41-4a4e-988c-4521d95de863"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"1edd10f4-3a41-4a4e-988c-4521d95de863"}],"recentChangeFlags":null},{"id":"d6613b8b-423a-4b7d-8108-697535a2b202","uri":"","name":"*.kinaxis.net/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"cc6da71d-1fd9-49f1-bc43-229e69c38981","sortOrder":1},"sortOrder":1,"tags":[{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"d6613b8b-423a-4b7d-8108-697535a2b202"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"d6613b8b-423a-4b7d-8108-697535a2b202"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"d6613b8b-423a-4b7d-8108-697535a2b202"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"d6613b8b-423a-4b7d-8108-697535a2b202"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"d6613b8b-423a-4b7d-8108-697535a2b202"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"d6613b8b-423a-4b7d-8108-697535a2b202"}],"recentChangeFlags":null},{"id":"c670eaf4-a6b5-4543-af1e-61af14415084","uri":"","name":"*.ai.kinaxis.net","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"94514092-4d31-45e1-b0b4-2aa4bf278705","sortOrder":2},"sortOrder":2,"tags":[{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"c670eaf4-a6b5-4543-af1e-61af14415084"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"c670eaf4-a6b5-4543-af1e-61af14415084"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"c670eaf4-a6b5-4543-af1e-61af14415084"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"c670eaf4-a6b5-4543-af1e-61af14415084"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"c670eaf4-a6b5-4543-af1e-61af14415084"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"c670eaf4-a6b5-4543-af1e-61af14415084"}],"recentChangeFlags":null},{"id":"c4f11412-aa1e-459b-a99b-4bf47009ee83","uri":"","name":"*vpn*.kinaxis.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f8e7f64f-a403-4c35-8e3f-34f8e6821ec5","sortOrder":3},"sortOrder":3,"tags":[{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"c4f11412-aa1e-459b-a99b-4bf47009ee83"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"c4f11412-aa1e-459b-a99b-4bf47009ee83"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"c4f11412-aa1e-459b-a99b-4bf47009ee83"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"c4f11412-aa1e-459b-a99b-4bf47009ee83"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"c4f11412-aa1e-459b-a99b-4bf47009ee83"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"c4f11412-aa1e-459b-a99b-4bf47009ee83"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch2\u003eAdditional Information\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003ePublic-Facing Web Properties\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eKinaxis’ main website (www.kinaxis.com) Only publicly accessible .com subdomains (e.g., blog.kinaxis.com, support.kinaxis.com, careers.kinaxis.com)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eUnintentional Internal Data Exposure\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePublicly exposed cloud storage buckets (e.g., Azure Blob Storage, GCS buckets, AWS S3) associated with Kinaxis domains\ncontaining internal or customer data\u003c/li\u003e\n\u003cli\u003ePublicly accessible internal documents, configuration files, or credentials inadvertently indexed or exposed (e.g., via Google dorking, exposed .git directories, .env files)\u003c/li\u003e\n\u003cli\u003eAPI endpoints that are publicly reachable without authentication and return sensitive internal or customer data\u003c/li\u003e\n\u003cli\u003eExposed debug pages, admin panels, or developer interfaces unintentionally reachable from the public internet\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"7211c71a-9d1a-4701-876b-e5e3b595f8a2","name":"Out of Scope","targets":[{"id":"7257edde-d6ef-41de-8e8f-e525c8845ed7","uri":"","name":"Anything not explicity listed as 'In Scope'","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3c4598b8-57e9-4def-aca5-e792df862069","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eOnly the domains that explicitly follow the pattern listed in the in-scope section are permitted for testing. Domains that are not listed are strictly out of scope and must not be tested.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eSystems \u0026amp; Portals\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eInternal corporate infrastructure not reachable from the public internet\u003c/li\u003e\n\u003cli\u003eSystems belonging to Kinaxis customers or third-party vendors\u003c/li\u003e\n\u003cli\u003eKinaxis employee endpoints, or internal tooling\u003c/li\u003e\n\u003cli\u003eAny third-party services where Kinaxis is not the primary controller (e.g., Salesforce, LinkedIn, Okta, Sharepoint etc)\n\n\u003cul\u003e\n\u003cli\u003eSome examples include kinaxis.okta.com, kinaxis.sharepoint.com etc.\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"e2338646-fb4f-4cc2-94ed-2a13a9907c9c","code":"kinaxis-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"a11a4e83-44ab-4b8e-afaf-09a1a3d68cc9","startsAt":"2026-07-21T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/7fd0/dfd5/566440cb/fecc39ff6eb02d05b3fd298f136f13fd_kinaxis_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-07-21T18:00:02.753Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/kinaxis-vdp-pro","changelogs":"/engagements/kinaxis-vdp-pro/changelog","submissions":null,"announcements":"/engagements/kinaxis-vdp-pro/announcements","hallOfFame":"/engagements/kinaxis-vdp-pro/hall_of_fames","crowdstream":"/engagements/kinaxis-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/kinaxis-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=kinaxis-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/kinaxis-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/kinaxis-vdp-pro/changelog","publishedAt":"2026-07-21T18:00:02.787Z","engagementChangelogUrl":"/engagements/kinaxis-vdp-pro/changelog/03997f62-b87f-48d5-92cc-7d4e0438df87","createUserFeedbacksUrl":"/engagements/kinaxis-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/kinaxis-vdp-pro/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}