SugarCRM · Vulnerability Disclosure
Sugarcrm Vulnerability Disclosure
Vulnerability disclosure
SugarCRM (SugarAI) runs a managed bug bounty program on HackerOne and publishes an RFC 9116 security.txt at the rebranded apex host. Both were verified live in this pass; the automated probe missed them in the prior round because it only checked the legacy sugarcrm.com hosts.
SugarCRM runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
CompanySaasCRMSalesMarketingCustomer ServiceSales AutomationREST APIWebhooksSales Intelligence
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
mailto:security@sugarcrm.com
Contact
mailto:secure@sugarcrm.com