Facebook Business Manager · Vulnerability Disclosure

Facebook Business Manager Vulnerability Disclosure

Vulnerability disclosure

Meta serves an RFC 9116 security.txt from both the consumer host and the Business Manager console host, and it points at a named, paid, public bug bounty program with a leaderboard. Re-probed and expanded 2026-08-13; the previous version of this file cited https://www.meta.com/.well-known/security.txt, which is a sibling host — the security.txt actually served on the hosts this profile covers is recorded below, with the full document saved verbatim.

Facebook Business Manager runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

AdvertisingAnalyticsBusiness ManagementMarketingSocial-MediaMessagingCommerceAgentsMCPWebhook
Program: Hackerone security.txt present

Disclosure Policy

Policy
Policy

Security Contact

Contact
https://www.facebook.com/whitehat/report/

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.facebook.com/.well-known/security.txt
specification: API Commons VulnerabilityDisclosure
specificationVersion: '0.1'
provider: Facebook Business Manager
providerId: facebook-business-manager
description: >-
  Meta serves an RFC 9116 security.txt from both the consumer host and the Business Manager console host, and
  it points at a named, paid, public bug bounty program with a leaderboard. Re-probed and expanded
  2026-08-13; the previous version of this file cited https://www.meta.com/.well-known/security.txt, which
  is a sibling host — the security.txt actually served on the hosts this profile covers is recorded below,
  with the full document saved verbatim.
security_txt:
  served: true
  hosts:
    - url: https://www.facebook.com/.well-known/security.txt
      status: 200
      fetched: '2026-08-13'
    - url: https://business.facebook.com/.well-known/security.txt
      status: 200
      fetched: '2026-08-13'
      note: Identical body to the www host.
  file: ../well-known/facebook-business-manager-security.txt
  expires: '2026-09-12T09:52:14-07:00'
  fields:
    contact: https://www.facebook.com/whitehat/report/
    acknowledgments: https://bugbounty.meta.com/leaderboard/
    hiring: https://www.metacareers.com/areas-of-work/security/
    policy:
      - https://bugbounty.meta.com/
      - https://about.meta.com/security/vulnerability-disclosure-policy
contact: https://www.facebook.com/whitehat/report/
policy:
  - https://bugbounty.meta.com/
  - https://about.meta.com/security/vulnerability-disclosure-policy
bug_bounty:
  program: Meta Bug Bounty
  url: https://bugbounty.meta.com/
  paid: true
  self_hosted: true
  platform: null
  platform_note: >-
    Meta runs its own program rather than using HackerOne, Bugcrowd or Intigriti.
  acknowledgments: https://bugbounty.meta.com/leaderboard/
  hall_of_fame: true
outbound_policy:
  name: Meta Vulnerability Disclosure Policy
  url: https://about.meta.com/security/vulnerability-disclosure-policy
  description: Meta's own policy for how it discloses vulnerabilities it finds in other products.
developer_incident_reporting:
  url: https://developers.facebook.com/incident/report/
  description: >-
    Separate channel for developers to report a platform data incident, distinct from the whitehat
    vulnerability channel.
evidence:
  - source: https://www.facebook.com/.well-known/security.txt
    kind: security.txt (live probe)
    status: 200
    fetched: '2026-08-13'
  - source: https://business.facebook.com/.well-known/security.txt
    kind: security.txt (live probe)
    status: 200
    fetched: '2026-08-13'
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com