Bonitasoft · Vulnerability Disclosure
Bonitasoft Vulnerability Disclosure
Vulnerability disclosure
Bonitasoft runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
CompanySoftware-as-a-ServiceBusiness Process ManagementProcess AutomationWorkflowsBPMNLow-CodeOpen-SourceOrchestrationAgentic AICase ManagementJava
Program: Hackerone
Disclosure Policy
Security Contact
Contact
product-security@ofelia.com
Source
Vulnerability Disclosure
generated: '2026-08-17'
method: searched
probe: true
source: https://documentation.ofelia.com/bonita/latest/contributing/vulnerability-reporting-policy
summary: >-
Bonitasoft/Ofelia publishes a real, named Vulnerability Reporting Policy inside
the Bonita documentation, with a dedicated security contact, a coordinated
disclosure timeline, and MITRE CVE coordination. It is NOT advertised at
/.well-known/security.txt (RFC 9116) on any host, and there is no bug bounty.
policy:
- https://documentation.ofelia.com/bonita/latest/contributing/vulnerability-reporting-policy
contact:
- product-security@ofelia.com
contact_note: >-
The address moved with the June 2026 rebrand. Third-party writeups and older
advisories cite bonitasecurity@bonitasoft.com; the current policy page names
product-security@ofelia.com. Use the current one.
process:
reporting: >-
Email the security team directly rather than disclosing publicly. A report
should state the reporter's attribution preference (name, pseudonym or
anonymous), a description of the suspected vulnerability, relevant source
links, the affected components and versions, and the system environment.
confidentiality: >-
Vulnerabilities and associated findings are classified as confidential
because they may compromise the integrity of other Bonita installations.
disclosure_timeline: >-
Once a fix ships across all maintained versions, subscription clients are
notified in advance. Two weeks after the fix (excluding holidays) the release
notes are updated publicly and the MITRE CVE entry is published. Community
Edition users may have to wait for the next community release.
cve_handling: >-
The Ofelia Security Team coordinates CVE assignment with MITRE. Reporters may
be credited in the release notes and in the MITRE report, though MITRE does
not typically list reporters in the public CVE entry.
scope: >-
Bonita technical vulnerabilities only. The policy states explicitly that it
"is not responsible for the whole security at Ofelia (infrastructures and
ofelia.com website are the responsibility of the IT Team)" — so an
infrastructure or website issue has no published intake path.
bug_bounty:
offered: false
checked: '2026-08-17'
evidence:
- {url: 'https://hackerone.com/bonitasoft', status: 404}
- {url: 'https://bugcrowd.com/bonitasoft', status: 404}
safe_harbour:
published: false
note: >-
No safe-harbour / authorized-testing statement appears in the policy. A
researcher gets a confidentiality expectation and a credit path, but no legal
assurance.
security_txt:
served: false
checked: '2026-08-17'
evidence:
- {url: 'https://www.ofelia.com/.well-known/security.txt', status: 404}
- {url: 'https://documentation.ofelia.com/.well-known/security.txt', status: 404}
- {url: 'https://api-documentation.ofelia.com/.well-known/security.txt', status: 404}
- {url: 'https://community.ofelia.com/.well-known/security.txt', status: 404}
- {url: 'https://www.bonitasoft.com/.well-known/security.txt', status: 404}
gap: >-
This is the cheapest fix on the whole profile. The policy, the contact and
the process all exist; publishing four lines at
https://www.ofelia.com/.well-known/security.txt (Contact, Policy, Expires,
Preferred-Languages) would make them machine-discoverable. NO SecurityTxt
pointer is emitted because nothing is served.
track_record:
note: >-
The policy is demonstrably exercised rather than decorative. Bonita 2026.2-u0
(2026-06-30) shipped two named security fixes with public CVE identifiers —
CVE-2026-7307 (keycloak-saml-core, crafted XML) and CVE-2026-2575
(keycloak-saml-adapter-core, application-level DoS) — published in the release
notes exactly as the policy describes. Bonita also has a long public CVE
history (e.g. CVE-2022-25237, authorization bypass leading to RCE in Bonita
Web 2021.2), which is what an actively researched open-source platform looks
like.
release_notes: https://documentation.ofelia.com/bonita/latest/release-notes
hardening_docs:
note: >-
Distinct from disclosure, the product ships a documented hardening surface
the vendor maintains:
pages:
- https://documentation.ofelia.com/bonita/latest/security/csrf-security
- https://documentation.ofelia.com/bonita/latest/security/brute-force-login-protection
- https://documentation.ofelia.com/bonita/latest/security/sanitizer-security
- https://documentation.ofelia.com/bonita/latest/security/java-security-policy
- https://documentation.ofelia.com/bonita/latest/security/enable-cors-in-tomcat-bundle
- https://documentation.ofelia.com/bonita/latest/identity/rest-api-authorization
- https://documentation.ofelia.com/cloud/latest/Security
evidence:
- {source: 'https://documentation.ofelia.com/bonita/latest/contributing/vulnerability-reporting-policy', kind: disclosure-policy, status: 200, checked: '2026-08-17'}
- {source: 'https://documentation.ofelia.com/bonita/latest/release-notes', kind: cve-publication, status: 200, checked: '2026-08-17'}
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/bonitasoft-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.