No reports yet — be the first to share your triage timing for Adobe Public.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
+ added 1 scope · Lightroom Video & Photo Editor (IOS)
− removed 2 scopes
{
"id": "c1a89c7e-5de0-435d-a30f-a8c16e65ccfc",
"url": "https://www.intigriti.com/programs/adobe/adobepublic/detail",
"name": "Adobe Public",
"handle": "adobepublic",
"status": "open",
"targets": {
"in_scope": [
{
"type": null,
"impact": "Tier 1",
"endpoint": "Acrobat PDF Spaces",
"description": "Relevant features include:\n\n* Acrobat PDF Spaces\n\n\nThese features are enabled on [acrobat.adobe.com](https://acrobat.adobe.com).\n\nTesting should focus on AI vulnerabilities with clear security impact, including prompt injection leading to sensitive content disclosure, unauthorized access to documents, unauthorized actions, cross-account access, data exfiltration, privilege escalation, or bypass of enforced backend security controls."
},
{
"type": null,
"impact": "Tier 1",
"endpoint": "Acrobat Create Presentations",
"description": "Relevant features include:\n\n* Acrobat Create Presentations\n\n\nThese features are enabled on [acrobat.adobe.com](https://acrobat.adobe.com).\n\nTesting should focus on AI vulnerabilities with clear security impact, including prompt injection leading to sensitive content disclosure, unauthorized access to documents, unauthorized actions, cross-account access, data exfiltration, privilege escalation, or bypass of enforced backend security controls."
},
{
"type": null,
"impact": "Tier 1",
"endpoint": "Acrobat Create Podcast",
"description": "Relevant features include:\n\n* Acrobat Create Podcast\n\nThese features are enabled on [acrobat.adobe.com](https://acrobat.adobe.com).\n\nTesting should focus on AI vulnerabilities with clear security impact, including prompt injection leading to sensitive content disclosure, unauthorized access to documents, unauthorized actions, cross-account access, data exfiltration, privilege escalation, or bypass of enforced backend security controls."
},
{
"type": null,
"impact": "Tier 1",
"endpoint": "Acrobat AI Assistant",
"description": "Relevant features include:\n\n* Acrobat AI Assistant\n* Acrobat PDF Spaces\n* Acrobat Create Presentations\n* Acrobat Create Podcast\n\nThese features are enabled on [acrobat.adobe.com](https://acrobat.adobe.com).\n\nTesting should focus on AI vulnerabilities with clear security impact, including prompt injection leading to sensitive content disclosure, unauthorized access to documents, unauthorized actions, cross-account access, data exfiltration, privilege escalation, or bypass of enforced backend security controls."
},
{
"type": null,
"impact": "Tier 1",
"endpoint": "Adobe Express AI Assistant",
"description": "Relevant feature:\n\n* Express AI Assistant\n\nEnabled on:\n\n[new.express.adobe.com](https://new.express.adobe.com)\n\nTesting should focus on AI-assisted content creation workflows, unauthorized actions, access control issues, data exposure, prompt injection with backend or security impact, and misuse of AI functionality that crosses user, account, or organisation boundaries."
},
{
"type": null,
"impact": "Tier 1",
"endpoint": "Lightroom AI Features",
"description": "Relevant features include:\n\n* Lightroom AI Edits\n* Lightroom “Edit suggestions” Tech Preview\n\nEnabled on:\n\n[lightroom.adobe.com](https://lightroom.adobe.com)\n\nTesting should focus on AI-powered photo editing workflows, unauthorized access to user content, cross-account data exposure, manipulation of user assets, and AI-related vulnerabilities with clear security impact."
},
{
"type": null,
"impact": "Tier 1",
"endpoint": "Adobe Firefly AI Features",
"description": "Relevant features include:\n\n* Firefly Image Models\n* Firefly Video Model\n* Firefly Custom Models\n\nEnabled on:\n\n[firefly.adobe.com\n](https://firefly.adobe.com)\n\nTesting should focus on AI vulnerabilities with practical security impact, including unauthorized access, data exposure, model or training-data security issues, prompt injection with backend impact, unauthorized actions, and cross-account or cross-tenant access."
},
{
"type": null,
"impact": "Tier 1",
"endpoint": "Photoshop AI Assistant",
"description": "Relevant feature:\n\n* Photoshop AI Assistant\n\nEnabled on:\n\n[photoshop.adobe.com](https://photoshop.adobe.com)\n\nTesting should focus on AI-assisted editing workflows, unauthorized access, data exposure, prompt injection with backend impact, and security issues affecting user assets or Photoshop Web workflows."
},
{
"type": null,
"impact": "Tier 1",
"endpoint": "Adobe Stock AI Studio",
"description": "Relevant feature:\n\n* Stock AI Studio\n\nEnabled on:\n\n[stock.adobe.com](https://stock.adobe.com)\n\nTesting should focus on AI-assisted Stock workflows, unauthorized access to assets, sensitive data exposure, cross-account access, and AI workflow manipulation with security impact."
},
{
"type": "ios",
"impact": "Tier 2",
"endpoint": "Frame.io iOS Application",
"description": null
},
{
"type": "ios",
"impact": "Tier 2",
"endpoint": "Adobe Fresco (iOS)",
"description": null
},
{
"type": "ios",
"impact": "Tier 2",
"endpoint": "Adobe Photoshop Express Mobile App (iOS)",
"description": null
},
{
"type": "ios",
"impact": "Tier 2",
"endpoint": "Lightroom Video & Photo Editor (IOS)",
"description": null
},
{
"type": "android",
"impact": "Tier 2",
"endpoint": "Lightroom Video & Photo Editor (Android)",
"description": null
},
{
"type": "ios",
"impact": "Tier 2",
"endpoint": "Adobe Scan Mobile App (iOS)",
"description": null
},
{
"type": "android",
"impact": "Tier 2",
"endpoint": "Adobe Scan Mobile App (Android)",
"description": null
},
{
"type": "ios",
"impact": "Tier 2",
"endpoint": "Acrobat Reader Mobile App (iOS)",
"description": null
},
{
"type": "android",
"impact": "Tier 2",
"endpoint": "Acrobat Reader Mobile App (Android)",
"description": null
},
{
"type": "wildcard",
"impact": "Tier 2",
"endpoint": "*.acrobat.adobe.com",
"description": "Type: Web\nTesting plan: Yes\nCredentials / subscription: Not provided; self-signup; free trial for premium features\n\n---\n\nAcrobat Web is in scope.\n\nTesting should focus on authentication, authorization, document access controls, sensitive document exposure, cross-account access, file handling, session handling, business logic flaws, and vulnerabilities affecting Acrobat Web users or documents.\n\nRelevant Tier 1 AI bonus features available through this asset include:\n\n* Acrobat AI Assistant\n* Acrobat PDF Spaces\n* Acrobat Create Presentations\n* Acrobat Create Podcast\n\nDocument Cloud Adobe Sign Web production environment .adobesign.com is out of scope for Acrobat Web testing."
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "stock.adobe.com",
"description": "Type: Web\nAssets: \n* stock.adobe.com\n* contributor.stock.adobe.com\n\nTesting plan: Yes\nCredentials / subscription: Not provided; self-signup; free trial for premium features\n\n---\n\nAdobe Stock and Contributor Stock are in scope.\n\nTesting should focus on authentication, authorization, account security, contributor workflows, unauthorized access to assets, sensitive data exposure, cross-account access, and business logic flaws affecting Stock or contributor workflows.\n\nRelevant Tier 1 AI bonus feature available through this asset:\n\n* Stock AI Studio"
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "firefly.adobe.com",
"description": "Type: Web\nAsset: firefly.adobe.com\nTesting plan: Yes\nCredentials / subscription: Not provided; self-signup; free trial for premium features\n\n---\n\nAdobe Firefly is in scope.\n\nTesting should focus on authentication, authorization, generated content workflows, user content access, sensitive data exposure, cross-account access, business logic flaws, and security issues affecting approved Firefly functionality.\n\nRelevant Tier 1 AI bonus features available through this asset include:\n\n* Firefly Image Models\n* Firefly Video Model\n* Firefly AI Specific Findings\n* Firefly Custom Models\n\nFirefly backend API IDORs related to jobs and data are out of scope where IDs are random UUID4 and short-lived."
},
{
"type": "wildcard",
"impact": "Tier 2",
"endpoint": "*.lightroom.adobe.com",
"description": "Type: Web\n\nAssets:\n* *.lightroom.adobe.com\n* photos.adobe.io\n\nTesting plan: Yes\nCredentials / subscription: Not provided; self-signup; free trial for premium features\n\n---\n\nLightroom Web is in scope.\n\nTesting should focus on authentication, authorization, user photo access controls, cross-account data exposure, sensitive metadata exposure, sharing workflow vulnerabilities, API authorization issues, and business logic flaws affecting Lightroom Web workflows.\n\nRelevant Tier 1 AI bonus features available through this asset include:\n\n* Lightroom AI Edits\n* Lightroom “Edit suggestions” Tech Preview\n\nOut-of-scope items:\n> Vulnerabilities related to Google Photos\n> Access/download image rendetions via API on disabled-download shares\n> Viewing another user's liked content via Lightroom Community API (Discover/Remix/Tutorials)\n> Public shares found via search engine indexing\n> Denial-of-service testing"
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "photoshop.adobe.com",
"description": "Type: Web\nAsset: photoshop.adobe.com\nTesting plan: Yes\nCredentials / subscription: Not provided; self-signup; free trial for premium features\n\n---\n\nPhotoshop Web is in scope.\n\nTesting should focus on authentication, authorization, access to user assets, cross-account access, file handling vulnerabilities, sensitive data exposure, Photoshop Web workflow abuse, and business logic flaws affecting Photoshop Web functionality.\n\nRelevant Tier 1 AI bonus feature available through this asset:\n\n* Photoshop AI Assistant\n\n> Researchers will be testing Photoshop Web in production and must not cause potential or actual denial of service. Third-party endpoints loaded by Photoshop Web are out of scope."
},
{
"type": "other",
"impact": "Tier 2",
"endpoint": "Adobe Commerce, Adobe Commerce B2B and Magento Open Source",
"description": "Type: Web\nTesting plan: Yes\nCredentials / subscription: Not provided; Magento Open Source option available\n\n---\n\nThis asset covers Adobe Commerce, Adobe Commerce B2B, Magento Open Source, core software in Magento 2 Commerce, Commerce B2B and Open Source default configuration, and bundled extensions.\n\nTesting should focus on server-side code execution, authentication and authorization issues, injection vulnerabilities, directory traversal, sensitive information disclosure, significant security misconfiguration, access control issues, and vulnerabilities affecting default configuration or bundled extensions.\n\n---\n\nResearchers who wish to test Adobe Commerce products may set up their own local or cloud development environment using the official Adobe installation guidance. Adobe Commerce and Adobe Commerce B2B require a valid Adobe Commerce license and access to the Adobe Composer repository. Magento Open Source is freely available for installation."
},
{
"type": "url",
"impact": "Tier 3",
"endpoint": "account.magento.com",
"description": null
},
{
"type": "url",
"impact": "Tier 3",
"endpoint": "commercemarketplace.adobe.com",
"description": null
},
{
"type": "url",
"impact": "Tier 3",
"endpoint": "repo.magento.com",
"description": null
},
{
"type": "url",
"impact": "Tier 3",
"endpoint": "magento.com",
"description": null
},
{
"type": "url",
"impact": "Tier 3",
"endpoint": "learningmanagerstage4.adobe.com",
"description": "Type: Web\nAsset: learningmanagerstage4.adobe.com\nTesting plan: Yes\nCredentials / subscription: Self-signup; free account covering all features\n\n---\n\nAdobe Learning Manager is in scope.\n\nTesting should focus on authentication, authorization, learning content workflows, role boundaries, sensitive data exposure, account access, and business logic flaws affecting approved learning workflows.\n\n> Testing must be performed against the provided stage environment. Production testing is out of scope.\n> Please carefully review the ALM-specific out-of-scope vulnerabilities listed in the testing plan attachment before starting your testing."
},
{
"type": "other",
"impact": "Tier 3",
"endpoint": "ColdFusion Administrator",
"description": "Type: Web\nTesting plan: Yes\nColdFusion Administrator is in scope.\n\n---\n\nTesting should focus on administrator security boundaries, authentication, authorization, privilege escalation, configuration access, sensitive configuration exposure, and vulnerabilities affecting restricted administrative functionality.\n\n> Researchers must follow the ColdFusion setup and Lockdown guidance before testing."
},
{
"type": "url",
"impact": "Tier 3",
"endpoint": "net.s2stagehance.com",
"description": "Type: Web\nAsset: net.s2stagehance.com\nTesting plan: Yes\nCredentials / subscription: Self-signup; free account covering all features\n\n---\n\nAdobe Behance is in scope.\n\nTesting should focus on authentication, authorization, account security, profile or project access controls, sensitive data exposure, and business logic flaws affecting approved Behance workflows.\n\n> Researchers must not test production www.behance.net, additional static-content domains, adobelogin.com, or other unrelated supporting domains unless explicitly listed."
},
{
"type": "url",
"impact": "Tier 3",
"endpoint": "new.express.adobe.com",
"description": "Type: Web\nAsset: new.express.adobe.com\nTesting plan: Yes\nCredentials / subscription: Not provided; self-signup; free trial for premium features\n\n---\n\nAdobe Express is in scope.\n\nTesting should focus on authentication, authorization, user content access, sensitive data exposure, API authorization, account or project boundary issues, and business logic flaws affecting approved Express workflows.\n\nRelevant Tier 1 AI bonus feature available through this asset:\n\n* Express AI Assistant\n\n> `express.adobe.com` and `express-embed.adobe.com` are out of scope. Denial-of-service testing is explicitly out of scope."
},
{
"type": "url",
"impact": "Tier 3",
"endpoint": "portfolio.ccpsx.com",
"description": "Type: Web\nAsset: portfolio.ccpsx.com\nTesting plan: Yes\nCredentials / subscription: Self-signup; free account covering all features\n\n---\n\nAdobe Portfolio is in scope.\n\nTesting should focus on authentication, authorization, portfolio workflow vulnerabilities, account boundary issues, sensitive data exposure, and business logic flaws affecting approved Portfolio workflows.\n\n> Researchers must not test production Portfolio websites, additional static-content domains, adobelogin.com, or other unrelated supporting domains unless explicitly listed."
},
{
"type": "url",
"impact": "Tier 3",
"endpoint": "fonts.adobe.com",
"description": "Type: Web\nAsset: fonts.adobe.com\nTesting plan: Yes\nCredentials / subscription: Self-signup; free account covering all features\n\n---\n\nAdobe Fonts is in scope.\n\nTesting should focus on authentication, authorization, account security, font access workflows, sensitive data exposure, and business logic flaws affecting Adobe Fonts functionality.\n\n> Digital Rights Management findings related to licensing bypasses are out of scope."
},
{
"type": "url",
"impact": "Tier 3",
"endpoint": "account.adobe.com",
"description": "Type: Web\n\nAssets:\n\n* ims-na1.adobelogin.com\n* adobeid-na1.services.adobe.com\n* auth.services.adobe.com\n* federatedid-na1.services.adobe.com\n* account.adobe.com\n\nTesting plan: Yes\nCredentials / subscription: Self-signup; free account covering all features\n\n---\n\nAdobe IMS and Adobe account security functionality are in scope.\n\nTesting should focus on identity flows, authentication, authorization, session handling, account security, security profile functionality, and identity-related vulnerabilities affecting approved IMS assets.\n\n> IMS-specific out-of-scope items apply, including denial-of-service testing, temporarily excluded IMS OAuth vulnerabilities, account.adobe.com Plans and Payment sections, and settings that are not Identity/IMS related."
},
{
"type": "url",
"impact": "Tier 3",
"endpoint": "auth.services.adobe.com",
"description": null
},
{
"type": "url",
"impact": "Tier 3",
"endpoint": "adobeid-na1.services.adobe.com",
"description": null
},
{
"type": "url",
"impact": "Tier 3",
"endpoint": "ims-na1.adobelogin.com",
"description": null
},
{
"type": "url",
"impact": "Tier 3",
"endpoint": "federatedid-na1.services.adobe.com",
"description": null
}
],
"out_of_scope": [
{
"type": "other",
"impact": "Out of scope",
"endpoint": "Adobe ColdFusion without ColdFusion Administrator",
"description": null
},
{
"type": "other",
"impact": "Out of scope",
"endpoint": "ColdFusion Administrator",
"description": null
}
]
},
"max_bounty": {
"value": 15000,
"currency": "USD"
},
"min_bounty": {
"value": 75,
"currency": "USD"
},
"tacRequired": false,
"company_handle": "adobe",
"twoFactorRequired": false,
"confidentiality_level": "public"
}stock.adobe.com· Tier 2firefly.adobe.com· Tier 2photoshop.adobe.com· Tier 2account.magento.com· Tier 3commercemarketplace.adobe.com· Tier 3repo.magento.com· Tier 3magento.com· Tier 3learningmanagerstage4.adobe.com· Tier 3net.s2stagehance.com· Tier 3new.express.adobe.com· Tier 3Lightroom Video & Photo Editor (Android)· Tier 2Adobe Scan Mobile App (Android)· Tier 2Acrobat Reader Mobile App (Android)· Tier 2Frame.io iOS Application· Tier 2Adobe Fresco (iOS)· Tier 2Adobe Photoshop Express Mobile App (iOS)· Tier 2Lightroom Video & Photo Editor (IOS)· Tier 2Adobe Scan Mobile App (iOS)· Tier 2Acrobat Reader Mobile App (iOS)· Tier 2Acrobat PDF Spaces· Tier 1Acrobat Create Presentations· Tier 1Acrobat Create Podcast· Tier 1Acrobat AI Assistant· Tier 1Adobe Express AI Assistant· Tier 1Lightroom AI Features· Tier 1Adobe Firefly AI Features· Tier 1Photoshop AI Assistant· Tier 1Adobe Stock AI Studio· Tier 1Adobe Commerce, Adobe Commerce B2B and Magento Open Source· Tier 2ColdFusion Administrator· Tier 3Adobe ColdFusion without ColdFusion AdministratorotherColdFusion Administratorother6d ago
first indexed
7d ago · 41 in-scope assets
auth.services.adobe.com· Tier 3