In this blog, I am going to share an account takeover vulnerability in a third-party provider widely used by many bug bounty programs.
I discovered this issue during a bug bounty engagement in October 2025. I discovered an IDOR leading to Account Takeover (ATO) in a third-party provider that works with many organizations.
before this Let me clear the concept first:
The provider is:
Root Cause
The application trusted client-controlled identity attributes without validating whether the supplied userId actually belonged to the authenticated user. This allowed an attacker to impersonate another Featurebase account.
New articles Dropping soon
Connect with me
Linkedin:
X/Twitter:
on Medium, where people are continuing the conversation by highlighting and responding to this story.
SOCIAL SHARE CARD GENERATOR