logo

How HackerOne Disproved an MFA Bypass With a Spot Check

ID: 895e0b52-4cfe-5cf4-b86a-e0785b6e6242

STIX ID: report--895e0b52-4cfe-5cf4-b86a-e0785b6e6242

Feed Name: HackerOne Blog

Threat Score
30/100

Date Published: 2024-11-27

Date Updated: 2026-06-12

...
...

HackerOne investigated an unverified claim of an MFA bypass by launching a Spot Check (a focused bug-hunting engagement). Selected researchers tested MFA and authentication flows, producing detailed writeups that increased confidence in the implementation and leading to the discovery and remediation of a medium-severity race condition in the 2FA reset process; no active exploitation or confirmed bypass was identified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.