Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
A security researcher discovered a broken access control vulnerability in Meta's support infrastructure that exposed customer support data. The flaw involved missing authorization, broken access control, and insecure direct object reference (IDOR) issues, allowing enumeration of support case numbers and access to support requests. Exploitable data included email and chat conversations, case details, submitted files, and personal information shared with Meta support. The vulnerability also allowed unauthorized creation and modification of support requests and workflows. Meta patched the issue in April 2026 and reported no evidence of malicious exploitation. The researcher received a $78,000 bounty for the discovery.
AI Analysis
Technical Summary
In January 2026, a security researcher reported a broken access control vulnerability affecting Meta's backend support infrastructure, initially believed limited to Meta Horizon Managed Solutions. Further analysis revealed a broader impact involving missing authorization and IDOR flaws. These could be chained to enumerate support case numbers and access sensitive customer support data, including communications, case details, files, and personal information. The vulnerability also permitted unauthorized creation and modification of support cases and workflows. Meta deployed patches in April 2026 and found no signs of exploitation in the wild. The researcher was awarded a significant bug bounty for the finding.
Potential Impact
The vulnerability exposed sensitive customer support data such as email and chat conversations, support case details, files submitted via support requests, and personal and contact information. It also allowed attackers to create support requests on behalf of organizations, modify support workflows including case statuses, and add unauthorized subscribers to support cases. This could lead to unauthorized disclosure and manipulation of customer support interactions and data.
Mitigation Recommendations
Meta rolled out patches addressing the vulnerability in April 2026. There is no evidence of exploitation in the wild. Organizations using Meta Horizon Managed Solutions or interacting with Meta support infrastructure should ensure they are operating with the updated, patched versions. No additional mitigation actions are indicated beyond applying the official patches.
Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
Description
A security researcher discovered a broken access control vulnerability in Meta's support infrastructure that exposed customer support data. The flaw involved missing authorization, broken access control, and insecure direct object reference (IDOR) issues, allowing enumeration of support case numbers and access to support requests. Exploitable data included email and chat conversations, case details, submitted files, and personal information shared with Meta support. The vulnerability also allowed unauthorized creation and modification of support requests and workflows. Meta patched the issue in April 2026 and reported no evidence of malicious exploitation. The researcher received a $78,000 bounty for the discovery.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In January 2026, a security researcher reported a broken access control vulnerability affecting Meta's backend support infrastructure, initially believed limited to Meta Horizon Managed Solutions. Further analysis revealed a broader impact involving missing authorization and IDOR flaws. These could be chained to enumerate support case numbers and access sensitive customer support data, including communications, case details, files, and personal information. The vulnerability also permitted unauthorized creation and modification of support cases and workflows. Meta deployed patches in April 2026 and found no signs of exploitation in the wild. The researcher was awarded a significant bug bounty for the finding.
Potential Impact
The vulnerability exposed sensitive customer support data such as email and chat conversations, support case details, files submitted via support requests, and personal and contact information. It also allowed attackers to create support requests on behalf of organizations, modify support workflows including case statuses, and add unauthorized subscribers to support cases. This could lead to unauthorized disclosure and manipulation of customer support interactions and data.
Mitigation Recommendations
Meta rolled out patches addressing the vulnerability in April 2026. There is no evidence of exploitation in the wild. Organizations using Meta Horizon Managed Solutions or interacting with Meta support infrastructure should ensure they are operating with the updated, patched versions. No additional mitigation actions are indicated beyond applying the official patches.
Technical Details
- Article Source
- {"url":"https://www.securityweek.com/meta-pays-78000-bounty-for-vulnerability-exposing-customer-support-data/","fetched":true,"fetchedAt":"2026-07-21T10:26:47.617Z","wordCount":1039}
Threat ID: 6a5f49672a4a8d5989f627e4
Added to database: 07/21/2026, 10:26:47 UTC
Last enriched: 07/21/2026, 10:26:53 UTC
Last updated: 07/21/2026, 15:11:58 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.