Back to directory
WRITEUP #6553

$1,500 PII Leak via GraphQL Field-Level Permission Bypass

Privilege Escalation
by@tinopreter(Clement (Tino) Osei-Somuah)
Bounty
$1,500
Published
Feb 26, 2026
Added to HackDex
Mar 9, 2026
Read Full Writeuphttps://medium.com/@tinopreter/1-500-pii-leak-via-graphql-field-level-permission-bypass-1e7ea2d1a019
RELATED WRITEUPS
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
Escalating From Reader To Contributor In Azure API Management
Privilege Escalation
Microsoft Windows MSI Installer - Repair to SYSTEM - A detailed journey
Privilege EscalationLocal Privilege Escalation
Hijacking SQL Server Credentials using Agent Jobs for Domain Privilege Escalation
Privilege Escalation
3CX Phone System Local Privilege Escalation Vulnerability
Privilege EscalationLocal Privilege Escalation

Built with ❤️ by Shubham Rawat