Mercedes-Benz Mercedes me · Vulnerability Disclosure

Mercedes Me Vulnerability Disclosure

Vulnerability disclosure

Mercedes-Benz runs a real vulnerability disclosure programme. It is NOT published on the developer portal or from any /.well-known path in the API estate — it is published from the Mercedes-Benz Group GitHub organisation's SECURITY.md, which points at a corporate "whitehat" policy page, and it is operated on Bugcrowd.

Mercedes-Benz Mercedes me runs a coordinated vulnerability disclosure program on Hackerone.

AutomotiveConnected CarConnected VehicleDaimlerFleet ManagementMercedes meMercedes-BenzOEMTelematicsVehicle Data
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy
Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-26'
method: searched
probe: true
source: https://raw.githubusercontent.com/mercedes-benz/.github/main/SECURITY.md
description: >-
  Mercedes-Benz runs a real vulnerability disclosure programme. It is NOT published on the developer
  portal or from any /.well-known path in the API estate — it is published from the Mercedes-Benz Group
  GitHub organisation's SECURITY.md, which points at a corporate "whitehat" policy page, and it is
  operated on Bugcrowd.
policy:
  published: true
  url: https://www.mercedes-benz.com/en/whitehat/
  name: Mercedes-Benz Vulnerability Reporting Policy
  first_party_pointer: https://raw.githubusercontent.com/mercedes-benz/.github/main/SECURITY.md
  quote: >-
    "It is the goal of Mercedes-Benz to offer its customers the best and most secure products such as
    connected cars and other services. Mercedes-Benz values the work of security researchers and whitehat
    hackers who spend time and effort helping us to achieve this goal."
bug_bounty:
  platform: Bugcrowd
  program: Mercedes-Benz Vulnerability Disclosure Engagement
  url: https://bugcrowd.com/engagements/mercedes-benz-vdp-ess
  type: vulnerability-disclosure
  paid: unknown
  note: >-
    Recorded as a disclosure engagement, which is what the Bugcrowd page title says. Whether it pays
    bounties was not established and is not claimed.
regional_programs:
  - platform: HackerOne
    program: Mercedes-Benz España Vulnerability Disclosure Policy
    url: https://hackerone.com/mercedes-benz_espana
    scope: regional (Spain)
security_txt:
  present: false
  note: >-
    No RFC 9116 security.txt is served from any host in the API estate. See
    well-known/mercedes-me-well-known.yml. A researcher who finds a flaw in api.mercedes-benz.com has no
    machine-discoverable contact from that host.
evidence:
  - url: https://raw.githubusercontent.com/mercedes-benz/.github/main/SECURITY.md
    status: 200
    kind: first-party security policy
    note: read verbatim; names the whitehat policy page as the reporting route
  - url: https://bugcrowd.com/engagements/mercedes-benz-vdp-ess
    status: 200
    kind: bug bounty / disclosure platform engagement
  - url: https://hackerone.com/mercedes-benz_espana
    status: 200
    kind: regional disclosure programme
  - url: https://www.mercedes-benz.com/en/whitehat/
    status: 403
    kind: disclosure policy page
    note: >-
      Akamai edge policy answers 403 to our probe regardless of User-Agent. The page is cited by
      Mercedes-Benz's own SECURITY.md, so it is treated as live-but-unreadable rather than dead.
  - url: https://developer.mercedes-benz.com/vulnerability-disclosure
    status: 200
    kind: none
    note: >-
      NOT EVIDENCE. This was recorded as a disclosure page in the 2026-07-11 round. It is a soft-404:
      developer.mercedes-benz.com answers 200 with an identical SPA shell for every path, and the only
      occurrences of the word "vulnerability" in that response are the URL echoed back in the og:url and
      twitter:url meta tags. Verified 2026-08-26 by diffing it against a fabricated path — the bodies are
      byte-identical once the URL is normalised. The keyword match that produced the original finding was
      matching our own request URL.
corrections:
  - date: '2026-08-26'
    what: >-
      Replaced a soft-404 false positive (developer.mercedes-benz.com/vulnerability-disclosure) with the
      real, first-party disclosure route. The programme is genuine; the evidence previously recorded for it
      was not.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/mercedes-me-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.