Bonitasoft · Vulnerability Disclosure

Bonitasoft Vulnerability Disclosure

Vulnerability disclosure

Bonitasoft runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanySoftware-as-a-ServiceBusiness Process ManagementProcess AutomationWorkflowsBPMNLow-CodeOpen-SourceOrchestrationAgentic AICase ManagementJava
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
product-security@ofelia.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-17'
method: searched
probe: true
source: https://documentation.ofelia.com/bonita/latest/contributing/vulnerability-reporting-policy
summary: >-
  Bonitasoft/Ofelia publishes a real, named Vulnerability Reporting Policy inside
  the Bonita documentation, with a dedicated security contact, a coordinated
  disclosure timeline, and MITRE CVE coordination. It is NOT advertised at
  /.well-known/security.txt (RFC 9116) on any host, and there is no bug bounty.

policy:
- https://documentation.ofelia.com/bonita/latest/contributing/vulnerability-reporting-policy
contact:
- product-security@ofelia.com
contact_note: >-
  The address moved with the June 2026 rebrand. Third-party writeups and older
  advisories cite bonitasecurity@bonitasoft.com; the current policy page names
  product-security@ofelia.com. Use the current one.

process:
  reporting: >-
    Email the security team directly rather than disclosing publicly. A report
    should state the reporter's attribution preference (name, pseudonym or
    anonymous), a description of the suspected vulnerability, relevant source
    links, the affected components and versions, and the system environment.
  confidentiality: >-
    Vulnerabilities and associated findings are classified as confidential
    because they may compromise the integrity of other Bonita installations.
  disclosure_timeline: >-
    Once a fix ships across all maintained versions, subscription clients are
    notified in advance. Two weeks after the fix (excluding holidays) the release
    notes are updated publicly and the MITRE CVE entry is published. Community
    Edition users may have to wait for the next community release.
  cve_handling: >-
    The Ofelia Security Team coordinates CVE assignment with MITRE. Reporters may
    be credited in the release notes and in the MITRE report, though MITRE does
    not typically list reporters in the public CVE entry.
  scope: >-
    Bonita technical vulnerabilities only. The policy states explicitly that it
    "is not responsible for the whole security at Ofelia (infrastructures and
    ofelia.com website are the responsibility of the IT Team)" — so an
    infrastructure or website issue has no published intake path.

bug_bounty:
  offered: false
  checked: '2026-08-17'
  evidence:
  - {url: 'https://hackerone.com/bonitasoft', status: 404}
  - {url: 'https://bugcrowd.com/bonitasoft', status: 404}

safe_harbour:
  published: false
  note: >-
    No safe-harbour / authorized-testing statement appears in the policy. A
    researcher gets a confidentiality expectation and a credit path, but no legal
    assurance.

security_txt:
  served: false
  checked: '2026-08-17'
  evidence:
  - {url: 'https://www.ofelia.com/.well-known/security.txt', status: 404}
  - {url: 'https://documentation.ofelia.com/.well-known/security.txt', status: 404}
  - {url: 'https://api-documentation.ofelia.com/.well-known/security.txt', status: 404}
  - {url: 'https://community.ofelia.com/.well-known/security.txt', status: 404}
  - {url: 'https://www.bonitasoft.com/.well-known/security.txt', status: 404}
  gap: >-
    This is the cheapest fix on the whole profile. The policy, the contact and
    the process all exist; publishing four lines at
    https://www.ofelia.com/.well-known/security.txt (Contact, Policy, Expires,
    Preferred-Languages) would make them machine-discoverable. NO SecurityTxt
    pointer is emitted because nothing is served.

track_record:
  note: >-
    The policy is demonstrably exercised rather than decorative. Bonita 2026.2-u0
    (2026-06-30) shipped two named security fixes with public CVE identifiers —
    CVE-2026-7307 (keycloak-saml-core, crafted XML) and CVE-2026-2575
    (keycloak-saml-adapter-core, application-level DoS) — published in the release
    notes exactly as the policy describes. Bonita also has a long public CVE
    history (e.g. CVE-2022-25237, authorization bypass leading to RCE in Bonita
    Web 2021.2), which is what an actively researched open-source platform looks
    like.
  release_notes: https://documentation.ofelia.com/bonita/latest/release-notes

hardening_docs:
  note: >-
    Distinct from disclosure, the product ships a documented hardening surface
    the vendor maintains:
  pages:
  - https://documentation.ofelia.com/bonita/latest/security/csrf-security
  - https://documentation.ofelia.com/bonita/latest/security/brute-force-login-protection
  - https://documentation.ofelia.com/bonita/latest/security/sanitizer-security
  - https://documentation.ofelia.com/bonita/latest/security/java-security-policy
  - https://documentation.ofelia.com/bonita/latest/security/enable-cors-in-tomcat-bundle
  - https://documentation.ofelia.com/bonita/latest/identity/rest-api-authorization
  - https://documentation.ofelia.com/cloud/latest/Security

evidence:
- {source: 'https://documentation.ofelia.com/bonita/latest/contributing/vulnerability-reporting-policy', kind: disclosure-policy, status: 200, checked: '2026-08-17'}
- {source: 'https://documentation.ofelia.com/bonita/latest/release-notes', kind: cve-publication, status: 200, checked: '2026-08-17'}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/bonitasoft-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.