$50,000 awarded on Auth0 by Okta, against *.cic-bug-bounty.auth0app.com.
Everything Bugcrowd published about this
- Programme
- Auth0 by Okta In our directory, so it has reviews and a grade.
- Platform handle
- auth0-okta
- Asset
- *.cic-bug-bounty.auth0app.com The specific asset the finding landed against, as the platform named it.
- Severity
- critical Bugcrowd rates P1–P5; this is that rating in HackerOne's words so the two feeds can sit in one table.
- Award
- $50,000 What the platform printed. Where a report carried more than one payment they are summed.
- Found by
- rexnets Named because the finder allowed the platform to name them.
- State
- unresolved — accepted, not yet fixed
- Accepted
- 28 September 2026 6 days ago. This is the date the programme accepted the finding.
- First seen here
- 29 September 2026 When our sweep first read this entry. It says nothing about the finding, only about us.
- Platform reference
- bd4f9099-8a75-4ad1-8b62-7255062c7cd2
Where this award sits
A single large number tells you nothing on its own. What matters is whether this programme pays like this routinely or whether this was the one time it did.
This is the largest award we have ever seen this programme publish, out of 19 awards. At 66.7× the median, it is well above what this programme normally prints.
Every figure here is drawn only from awards a platform chose to publish, which is a minority of what gets paid. Read the median as "of the payouts made public", never as "what this programme pays".
What else rexnets has published on Bugcrowd
- Gearset: Managed Bug Bounty medium · staging.claytonapp.com · 2 months ago —
- Fivetran medium · *.fivetran.com · 3 months ago —
- Atlassian medium · Any associated *.atlassian.com or *.atl-paas.net domain that can be exploited DIRECTLY from the *.atlassian.net instance · 3 months ago —
- Atlassian high · Any associated *.atlassian.com or *.atl-paas.net domain that can be exploited DIRECTLY from the *.atlassian.net instance · 3 months ago —
- Fivetran low · *.fivetran.com · 4 months ago —
- Atlassian medium · Any associated *.atlassian.com or *.atl-paas.net domain that can be exploited DIRECTLY from the *.atlassian.net instance · 6 months ago —
- Aiven Managed Bug Bounty medium · Aiven for OpenSearch · 6 months ago —
- Atlassian medium · Any associated *.atlassian.com or *.atl-paas.net domain that can be exploited DIRECTLY from the *.atlassian.net instance · 6 months ago —
Counted within Bugcrowd only. The same handle on another platform may or may not be the same person, and this page will not assume it is.
What else Auth0 by Okta has published
- Auth0 PHP SDK (auth0-php) low · unresolved · johanw · 23 days ago $750
- Auth0 SDK for Web (Auth0.js) low · unresolved · withheld · 23 days ago —
- Auth0 Single Page App SDK (auth0-spa-js) medium · unresolved · yud4s · 23 days ago $750
- manage.cic-bug-bounty.auth0app.com (Management Dashboard) low · unresolved · withheld · 23 days ago —
- Auth0 Single Page App SDK (auth0-spa-js) low · unresolved · withheld · 23 days ago —
- Auth0 SDK for Web (Auth0.js) low · unresolved · withheld · 23 days ago —
- https://play.fga.dev/ medium · unresolved · yud4s · 23 days ago $1,000
- Auth0 PHP SDK (auth0-php) medium · unresolved · withheld · 23 days ago $1,000
Where this came from. One row of a public platform feed, stored as published and never edited. We hold no report title, no write-up and no reproduction steps, because the feeds do not carry them and we do not go looking for them. A withheld name stays withheld; if a finder later asks the platform to un-name them, the next sweep un-names them here. Absence of an award figure is publication policy, not evidence a programme did not pay.