{"id":"71717aae-178d-4ae9-861f-390d797fc821","engagementId":"c7bcd6c7-2690-44d7-94d6-3475a9b49c60","data":{"brief":{"id":"72897772-805d-4b8f-952a-edf5f9a9a7a3","name":"McDonald's Vulnerability Disclosure Engagement","tagline":"McDonald’s is the world’s leading global foodservice retailer with over 37,000 locations in over 100 countries.","description":"\u003cp\u003e\u003cstrong\u003eEffective: February 9th, 2026\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eMcDonald’s Corporation, and its subsidiaries, affiliates, developmental licensees and franchisees (collectively, “McDonald’s”) are committed to privacy and security. The McDonald’s Vulnerability Disclosure Policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities and to convey our preferences in how to submit discovered vulnerabilities to us.\u003c/p\u003e\n\n\u003cp\u003eThis Policy describes what systems and types of research are covered under this Policy, how to send us vulnerability reports, and how long we ask security researchers to wait before publicly disclosing vulnerabilities.\u003c/p\u003e\n\n\u003cp\u003eWe encourage you to contact us to report potential vulnerabilities in our systems. We appreciate your efforts in helping protect customer trust and make McDonald’s more secure.\u003c/p\u003e\n\n\u003ch2\u003eReport Requirements\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eIn order to help us triage and prioritize submissions, we ask that you:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDescribe the location the vulnerability was discovered and the potential impact of exploitation.\u003c/li\u003e\n\u003cli\u003eProvide technical information, including URL(s) affected by the bug, a detailed description of the steps needed to reproduce the vulnerability (proof of concept (PoC) scripts or screenshots are helpful), any specific tools or software used in the discovery of the bug, attachments (e.g., screenshots, logs, or code snippets), whether you identified any potential attack scenarios that could exploit this bug and, if so, a description, and any technical HTTP/application requests outputs (e.g., Burp, Caido, Wireshark, Postman).\u003c/li\u003e\n\u003cli\u003eProvide bug details, including a name or brief description of the discovered bug, category of the bug (e.g., Cross-Site Scripting, SQL Injection, etc.), severity level of the bug (Critical, High, Medium, Low), and date and time of bug discovery.\u003c/li\u003e\n\u003cli\u003eProvide an impact assessment, including potential consequences if the bug is exploited (e.g., data loss, unauthorized access, etc.), mitigation and remediation, proposed mitigation measures or solutions for the discovered bug, whether you attempted to contact the vendor or affected parties prior to submitting this report and, if so, details of such communication, and any additional comments or information that you think might be helpful in evaluating your submission.\u003c/li\u003e\n\u003cli\u003eProvide your report in English, if possible.\u003c/li\u003e\n\u003cli\u003eShare your contact information, including your full name (optional), email address, preferred contact method, bug bounty hunter username (if applicable), and affiliated organization (if applicable) so that we can coordinate with you.\u003c/li\u003e\n\u003cli\u003eDo not share information about your findings with third parties or publicly disclose until we confirm that they have been remediated and we have provided prior written approval.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eHow We Handle Reports\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe will acknowledge that your report has been received within 10 business days.\u003c/li\u003e\n\u003cli\u003eWhen practicable, we will confirm the existence of the vulnerability and provide you with updates on the remediation process.\u003c/li\u003e\n\u003cli\u003eWe will maintain an open dialogue to discuss issues.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRules of Engagement\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eNotify us as soon as possible after you discover a real or potential security issue.\u003c/li\u003e\n\u003cli\u003eDo not access, view, or download any personal information.\u003c/li\u003e\n\u003cli\u003eDo not violate any applicable laws, which may include but are not limited to applicable privacy laws.\u003c/li\u003e\n\u003cli\u003eDo not degrade the user experience, disrupt production systems, or destroy or manipulate any data.\u003c/li\u003e\n\u003cli\u003ePerform the minimum amount of testing necessary to identify and validate the finding.\n\n\u003cul\u003e\n\u003cli\u003eDo not perform additional testing after you have confirmed that a vulnerability exists. \u003c/li\u003e\n\u003cli\u003eDo not attempt to conduct post-exploitation, including but not limited to modification or destruction of data, interruption or degradation of McDonald’s services, or pivoting with access not normally granted. \u003c/li\u003e\n\u003cli\u003eDo not use an exploit to compromise or exfiltrate data, establish persistent access, or pivot to other systems. \u003c/li\u003e\n\u003cli\u003eIf you discover a vulnerability that could allow you to bypass an authentication control and gain access to another account, immediately report the vulnerability and do not take further action with the other account or its data.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eIf a vulnerability or your testing causes a readily visible issue that could alert the public to the vulnerability or your testing, stop further testing and immediately report the issue to McDonald’s, even if your report is incomplete.\u003c/li\u003e\n\u003cli\u003eUse only your own accounts while testing. Do not compromise or test McDonald’s accounts that are not your own.\u003c/li\u003e\n\u003cli\u003eOnce you have demonstrated and reported a vulnerability, do not attempt to reproduce the finding again except to the extent requested in writing by McDonald’s.\u003c/li\u003e\n\u003cli\u003eProvide McDonald’s a reasonable amount of time to resolve the issue, and do not disclose publicly or to a third party without obtaining prior written approval from McDonald’s.\u003c/li\u003e\n\u003cli\u003eDo not submit a high volume of low-quality reports.\u003c/li\u003e\n\u003cli\u003eDo not use third-party sites when testing; only utilize infrastructure that you expressly own and control yourself.\u003c/li\u003e\n\u003cli\u003eComply with all provisions of this Policy at all times.\u003c/li\u003e\n\u003cli\u003eTest only in-scope assets, systems, services and products. Do not test out-of-scope assets, systems, services and products, and do not test with disallowed methods.\u003c/li\u003e\n\u003cli\u003eEmployees of McDonald’s will report potential security vulnerabilities through McDonald’s internal processes and in accordance with McDonald’s applicable policies and procedures.\u003c/li\u003e\n\u003cli\u003eReports, which may include but are not be limited to the following, \u003cstrong\u003ewill generally be considered informational\u003c/strong\u003e:\n\n\u003cul\u003e\n\u003cli\u003eOpen redirects without proven impact (e.g., no token leakage, no authorization bypass, no SSRF, no phishing scenario tied to an authenticated workflow).\u003c/li\u003e\n\u003cli\u003eClickjacking on non‑sensitive pages (i.e., pages with no sensitive data or privileged actions).\u003c/li\u003e\n\u003cli\u003eUnauthenticated, logout, or login CSRF that does not change sensitive state or bypass protection.\u003c/li\u003e\n\u003cli\u003eInsecure Direct Object Reference (IDOR) without impact (e.g., disclosing non‑sensitive numeric IDs alone). \u003cstrong\u003eNote\u003c/strong\u003e: User ID exposure by itself is typically low; if you can chain it into account takeover or sensitive data access, submit as a single chained report with a working PoC.\u003c/li\u003e\n\u003cli\u003eLow‑impact session management findings that do not lead to account compromise or privilege escalation.\u003c/li\u003e\n\u003cli\u003eRole‑Based Access Control (RBAC) “multi‑role” duplicates - submit one representative example per endpoint lacking enforcement; duplicates across roles are considered the same issue.\u003c/li\u003e\n\u003cli\u003eRace conditions with no proven impact (e.g., no double‑spend, no privilege change, no unauthorized actions).\u003c/li\u003e\n\u003cli\u003eAbsence of certificate pinning, code obfuscation, or jailbreak/root detection by itself\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eThe following forms of testing are not allowed\u003c/strong\u003e:\n\n\u003cul\u003e\n\u003cli\u003eDo not engage in disruptive testing, including but not limited to Denial of service (DoS or DDoS) tests, or any other actions or tests that could impair access to or damage a system or data or impact confidentiality, integrity or availability of information and systems.\u003c/li\u003e\n\u003cli\u003eLimited usage of automated scanners/tools is allowed, but automated scanners/tools will be configured to not send more than 5 requests per second to any particular service.\u003c/li\u003e\n\u003cli\u003ePhysical testing (e.g. office access, open doors, tailgating), social engineering (e.g. phishing, vishing), or any other non-technical vulnerability testing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eTechnical items, which may include but are not limited to the following, are \u003cstrong\u003econsidered out-of-scope and not valid reports\u003c/strong\u003e:\n\n\u003cul\u003e\n\u003cli\u003eSubmissions purely detected by artificial intelligence tools or models with no manual verification are out of scope.\u003c/li\u003e\n\u003cli\u003eAutomated scanner output (raw or unvalidated) and bulk scanning are out of scope. McDonald’s requires manually validated findings with a clear, reproducible impact and PoC.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAdditional reports that will be \u003cstrong\u003erejected due to out-of-scope may include\u003c/strong\u003e but are not limited to:\n\n\u003cul\u003e\n\u003cli\u003eMissing or weak security headers (generic) without exploitability (e.g., generic CSP, X‑Frame‑Options, HSTS recommendations absent a working exploit).\u003c/li\u003e\n\u003cli\u003eCookies missing HttpOnly/Secure for non‑sensitive cookies only.\u003c/li\u003e\n\u003cli\u003eContent spoofing or text injection without the ability to modify HTML/CSS or cause a security impact (e.g., self‑XSS, self‑HTML injection, non‑persistent UI text changes).\u003c/li\u003e\n\u003cli\u003eCache‑control issues on non‑sensitive pages.\u003c/li\u003e\n\u003cli\u003ePresence of browser autocomplete on form fields (without security impact).\u003c/li\u003e\n\u003cli\u003eOPTIONS / TRACE HTTP methods enabled without an exploit path.\u003c/li\u003e\n\u003cli\u003eSocial‑engineering‑dependent attacks against employees or vendors.\u003c/li\u003e\n\u003cli\u003eSSL/TLS “best practice” gaps without a working exploit (e.g., ciphers/hardening recommendations).\u003c/li\u003e\n\u003cli\u003eAttacks requiring Man‑in‑the‑Middle (MitM), device compromise, or physical access to a user’s device.\u003c/li\u003e\n\u003cli\u003eAny activity that could disrupt service (e.g., DoS, DDoS, resource‑exhaustion tests).\u003c/li\u003e\n\u003cli\u003eUse of outdated or known‑vulnerable software/libraries without a working PoC or demonstrated impact.\u003c/li\u003e\n\u003cli\u003eEmail authentication configuration (DMARC, DKIM, SPF) issues without demonstrated abuse leading to security impact.\u003c/li\u003e\n\u003cli\u003eCache poisoning without impact; CPDoS (Cache‑Poisoned DoS) is out of scope.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"ed347696-07e6-4878-8ae8-d9c099ab6d99","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to McDonalds, you can report it to this engagement for our review. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eReport Guidelines\u003c/h2\u003e\n\n\u003cp\u003eAll reports must include the following details: \u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eBug Details:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eName or brief description of the discovered bug: \u003c/li\u003e\n\u003cli\u003eCategory of the bug (e.g., Cross-Site Scripting, SQL Injection, etc.): \u003c/li\u003e\n\u003cli\u003eSeverity level of the bug (Critical, High, Medium, Low):\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eDate and time of bug discovery: \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eTechnical Information:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eURL(s) affected by the bug:\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eSteps to reproduce the bug (please provide detailed instructions):\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eAny specific tools or software used in the discovery of the bug:\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eAttachments (e.g., screenshots, logs, or code snippets):\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eHave you identified any potential attack scenarios that could exploit this bug? If so, please describe: \u003c/li\u003e\n\u003cli\u003eAny technical HTTP/application requests outputs (e.g., Burp, Caido, Wireshark, Postman):\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eImpact Assessment:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003ePotential consequences if the bug is exploited (e.g., data loss, unauthorized access, etc.)\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo not submit more than one vulnerability per report. In cases where demonstrating impact requires chaining multiple vulnerabilities together, those can be included in the same report as long as the linkage is clearly explained\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eWe do not accept reports that contain low-effort or AI-generated content. Submissions must demonstrate original analysis, clear understanding of the issue, and actionable detail. Reports lacking meaningful human input will be rejected\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eAll targets within scope are publicly accessible.\u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cp\u003eWhen N-Day bugs are released to the public, please let us know. Each report will be reviewed on a case-by-case basis.\u003c/p\u003e\n\n\u003ch2\u003eLeaked Credentials\u003c/h2\u003e\n\n\u003cp\u003eSubmissions related to leaked or exposed employee credentials (e.g., dark web forums, credential dumps) will be reviewed on a case-by-case basis. \u003cstrong\u003eThe use of any leaked credentials during testing is strictly prohibited and may result in disqualification from the bounty program.\u003c/strong\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\u003c/li\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting bypass attempts\u003c/li\u003e\n\u003cli\u003eEmail bombing or flooding\u003c/li\u003e\n\u003cli\u003eALL forms of social Engineering\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eBug Bounty\u003c/h2\u003e\n\n\u003cp\u003eCurrently, McDonald’s does not have a bug bounty program, and we do not provide bounties, payments, or other incentives or rewards in connection with reported vulnerabilities.\u003c/p\u003e\n\n\u003ch2\u003eQuestions\u003c/h2\u003e\n\n\u003cp\u003eQuestions regarding this Policy may be sent to the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e.\u003c/p\u003e","safeHarborStatus":null,"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"397d5ed5-64ed-484d-81c6-afa3c55b0a1d","name":"In Scope ","targets":[{"id":"2de8fa36-c017-427d-bdc6-a237e9792441","uri":"","name":"*mcd.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"503820e7-815f-43d8-880a-973520dbc199","sortOrder":0},"sortOrder":0,"tags":[{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"2de8fa36-c017-427d-bdc6-a237e9792441"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"2de8fa36-c017-427d-bdc6-a237e9792441"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2de8fa36-c017-427d-bdc6-a237e9792441"}],"recentChangeFlags":null},{"id":"0664bc70-210e-479a-ada4-fc6ca4d96e44","uri":"","name":"*mcdonalds.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"79e89bb7-f0a1-444b-a887-6a2acbdaa4d0","sortOrder":1},"sortOrder":1,"tags":[{"id":"08e84ba6-1e84-4c11-b559-a3b3b963546f","name":"Akamai CDN","targetId":"0664bc70-210e-479a-ada4-fc6ca4d96e44"},{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"0664bc70-210e-479a-ada4-fc6ca4d96e44"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"0664bc70-210e-479a-ada4-fc6ca4d96e44"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch2\u003eScope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eAny externally accessible application, domain, or digital asset associated with McDonalds is considered in scope. This includes assets where the domain or hostname does not contain McDonalds branding, provided they can be reasonably linked to McDonalds which may include but is not limited to *.mcdonalds.com and *.mcd.com.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAny service not included in the scope above is excluded from scope and is not authorized for testing. If you become aware of an out-of-scope vulnerability, you may report the security finding for our review.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"c7bcd6c7-2690-44d7-94d6-3475a9b49c60","code":"mcdonalds","state":"in_progress","endsAt":null,"bountyId":"27d24528-bc05-4f5e-a593-924a27a736b8","startsAt":"2026-02-12T15:03:51Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Food and Beverage","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/28bd/d886/6166098f/a213b3696a915f8f9bfda63bee0e731a_mcdonalds_corporation_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-02-12T15:03:51.646Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/mcdonalds","changelogs":"/engagements/mcdonalds/changelog","submissions":null,"announcements":"/engagements/mcdonalds/announcements","hallOfFame":"/engagements/mcdonalds/hall_of_fames","crowdstream":null},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/mcdonalds/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=mcdonalds\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/mcdonalds/engagement_subscribers","engagementChangelogsUrl":"/engagements/mcdonalds/changelog","publishedAt":"2026-03-12T20:20:42.060Z","engagementChangelogUrl":"/engagements/mcdonalds/changelog/71717aae-178d-4ae9-861f-390d797fc821","createUserFeedbacksUrl":"/engagements/mcdonalds/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}