Description

Adobe Bug Bounty Program — Launching September 1st on Intigriti Hello and welcome, researchers! We're excited to announce that the Adobe Bug Bounty Program officially launches on Intigriti on September 1st. We're bringing our program to the Intigriti community and can't wait to collaborate with you. A huge welcome to both our returning researchers joining us here and the new members of the community — your work plays a critical role in helping keep Adobe's products and customers secure, and we're grateful to have you on board. Thank you for being part of this next chapter with us. See you on September 1st!

Bounties
Low
0.1 - 3.9
Medium
4.0 - 6.9
High
7.0 - 8.9
Critical
9.0 - 9.4
Exceptional
9.5 - 10.0
Tier 1
min. $
max. $
150
300
300
1,500
1,500
7,500
7,500
10,000
10,000
15,000
Tier 1
$150 - $15,000
Tier 2
min. $
max. $
100
250
250
1,000
1,500
5,000
5,000
7,500
7,500
10,000
Tier 2
$100 - $10,000
Tier 3
min. $
max. $
75
100
100
500
500
1,500
1,500
3,000
3,000
5,000
Tier 3
$75 - $5,000

To be eligible for a reward, a report must:

  • Concern an asset that is in scope
  • Concern a vulnerability type that is eligible under this policy
  • Be previously unknown to Adobe
  • Be valid and reproducible
  • Be the first such report received
  • Include enough detail for Adobe to reproduce and validate the issue
  • Include the researcher’s testing IP address

Reward Calculation Rules

  • One issue receives one bounty.
  • Multiple submissions caused by a single root cause (one flaw reachable via multiple parameters, endpoints, or locations, resolved by the same fix) are treated as one finding and awarded a single bounty.
  • Where submissions reveal a general class/pattern of weakness across distinct locations or components within the same product or shared codebase (each potentially requiring its own fix), the first two valid reports (by submission time, across all researchers) are each eligible for a full bounty at their individually assessed severity; subsequent reports of the same pattern are acknowledged (e.g., Hall of Fame points) but not separately rewarded.
    Example — pattern across distinct locations (same product, separate fixes):
    Reports A, B, and C each hit a different service in the same product, all caused by the same underlying weakness type but each requiring its own fix.
    A and B — the first two to establish the pattern → each eligible for a full bounty, at its own assessed severity.
    C (and any further reports of the same pattern) → acknowledged (e.g., Hall of Fame points) but not separately rewarded, as the two-report cap has been reached.
  • Scope is determined by the affected asset and demonstrated impact, not by which Adobe team remediates the issue. An exception applies to products that integrate IMS: when both the vulnerability and the required remediation reside within IMS, the issue will be classified and rewarded as an IMS issue.
  • ATO payouts rules:
ATO type Impact Payout
Cross-Tenant / Cross-Organization ATO account or session compromise affecting users outside the attacker's own organization/tenant full bounty based on the assessed severity
Same-Tenant / Single-Account ATO ATO limited to a single user account (including IMS token theft affecting multiple Adobe products for one user) or within the same organizational context The first confirmed, unique ATO technique receives a discretionary bonus on top of the bounty awarded for the underlying vulnerability's severity (scored without the ATO impact). Subsequent reports using the same or substantially similar technique will be assessed and paid based solely on the underlying vulnerability's severity, without the ATO discretionary bonus.
  • If either the underlying vulnerability or resulting impact has already been reported and validated, subsequent reports demonstrating the same vulnerability or materially similar impact chain will be considered duplicates for that component.
  • For AEM, researchers are encouraged to validate across Cloud Service, Managed Services, and LTS where applicable. A bonus may apply where the issue is validated across all platforms.
Rules of engagement
Not applicable
User-Agent: <standard browser/tool user agent> <intigriti:{Username}>
max. 20 requests /sec
X-Intigriti-Username: {Username}

By participating in this program, you agree to:

  • Respect the Community Code of Conduct
  • Respect the Intigriti Terms and Conditions
  • Respect the scope of the program
  • Not discuss or disclose vulnerability information without prior written consent (including PoC's on YouTube and Vimeo)

Program Policy

  • Researchers who are the first to report a vulnerability will be the researcher acknowledged in the release notes once the vulnerability is resolved. If there are additional team members involved in researching the vulnerability, please provide their name(s) and what their contribution was to the findings when submitting this report.
  • AI-assisted discovery is allowed but the researcher must have validated the finding themselves. Unvalidated AI-generated output describing a plausible but unconfirmed vulnerability will be closed as N/A, which may result in the researcher losing reputation points or potentially being banned from our program.
  • If either the underlying vulnerability (e.g., XSS) or the resulting impact (e.g., ATO) has already been reported and validated, subsequent reports demonstrating the same vulnerability or materially, similar impact chain will be considered duplicates for that component, and only any newly identified element will be eligible for evaluation.

Validation times

We will validate all submissions within the below timelines, once your submission has been verified by Intigriti.
Submissions validated outside of this may be awarded a €25 bonus.

Vulnerability Severity Time to validate
Exceptional 2 Working days
Critical 2 Working days
High 5 Working days
Medium 15 Working days
Low 15 Working days

This remains at the discretion of Adobe Inc to award.

Assets
9
Adobe AI (Bonus Tier 1)
Acrobat PDF Spaces
AI Model
Tier 1
Acrobat Create Presentations
AI Model
Tier 1
Acrobat Create Podcast
AI Model
Tier 1
Acrobat AI Assistant
AI Model
Tier 1
Adobe Express AI Assistant
AI Model
Tier 1
Lightroom AI Features
AI Model
Tier 1
Adobe Firefly AI Features
AI Model
Tier 1
Photoshop AI Assistant
AI Model
Tier 1
Adobe Stock AI Studio
AI Model
Tier 1
9
Mobile Applications

In scope:

  • Acrobat Reader Mobile App - Android and iOS
  • Adobe Scan Mobile App - Android and iOS
  • Lightroom Mobile App - Android and iOS
  • Adobe Photoshop Express Mobile App - iOS
  • Adobe Fresco - iOS
  • Frame.io iOS Application - iOS

Testing should focus on mobile application security issues with practical impact, including authentication, authorization, session handling, sensitive data exposure, API authorization, and vulnerabilities affecting user photos or account data.


  • Researchers must review and follow the attached Adobe VIP Test Plan Attachment before testing any mobile application.

  • The attachment contains the relevant product-specific setup instructions, access requirements, account requirements, limitations, and product-specific exclusions. Where test accounts or provisioned access are required, researchers must only use the approved test accounts, roles, and environments described in the relevant test plan.

  • Mobile submissions that rely on rooted or jailbroken devices, malicious APK installation, or mobile OAuth secret leaks without meaningful access or impact are out of scope unless Adobe explicitly confirms otherwise.

1
Acrobat Web
*.acrobat.adobe.com
Wildcard
Tier 2
1
Adobe Stock
1
Adobe Firefly
2
ColdFusion

Type: Web
Testing plan: Yes
Credentials / subscription: Not provided; free trial option


Testing should focus on server-side code execution, authentication and authorization flaws, injection vulnerabilities, directory traversal, sensitive information disclosure, significant security misconfiguration, and vulnerabilities affecting supported ColdFusion server functionality.

Reports against ColdFusion without the Lockdown installer in place are out of scope. Adobe recommends testing on the latest available version.

Out-of-scope:
ColdFusion API Manager, CFFiddle, coldfusion.adobe.com
RDS-dependent findings: Vulnerabilities reachable only when Remote Development Services (RDS) is enabled.

Adobe ColdFusion without ColdFusion Administrator
Other
Tier 2
ColdFusion Administrator
Other
Tier 3
1
Lightroom Web
*.lightroom.adobe.com
Wildcard
Tier 2
1
Photoshop Web
5
Adobe Commerce/Magento
Adobe Commerce, Adobe Commerce B2B and Magento Open Source
Other
Tier 2
URL
Tier 3
1
Adobe Learning Manager
1
ColdFusion Administrator
ColdFusion Administrator
Other
Tier 3
1
Adobe Behance
1
Adobe Express
1
Adobe Portfolio
1
Adobe Fonts
In scope

Introduction

We are happy to announce the Adobe Public Bug Bounty Program.

Adobe welcomes contributions from security researchers to help protect Adobe customers, products, services, content workflows, creative applications, document workflows, AI-enabled features, mobile applications, and approved testing environments.

Researchers should focus only on approved Adobe assets and testing environments listed in this program. Testing must follow the relevant product-specific test plan and must remain limited to approved assets, accounts, environments, roles, and functionality.

Our worst-case scenarios are:

We encourage coordinated disclosure of vulnerabilities with practical security impact, including:

  • Remote code execution (RCE)
  • SQL/command/LDAP injection and other injection vulnerabilities
  • Server-Side Request Forgery (SSRF)
  • Cross-site scripting (XSS)
  • Cross-site request forgery (CSRF) in a privileged context
  • Directory traversal
  • Authentication and session management flaws
  • Authorization flaws, including IDOR, cross-account access, and privilege escalation
  • Account takeover
  • Unauthorized access to customer or user data
  • Sensitive file, document, media, or asset exposure
  • Information disclosure with meaningful security impact
  • Security misconfiguration resulting in unauthorized access or data exposure
  • Prompt injection leading to sensitive data disclosure, privilege escalation, or unauthorized tool use
  • AI-specific vulnerabilities with real backend impact (authorization bypass, data exposure, tool-use abuse)

Tier Guidance

Tier 1 - AI Bonus Tier
This applies to approved Adobe AI bonus features where the report demonstrates clear AI, agentic, MCP, model, training-data, supply-chain, data exposure, privilege escalation, unauthorized action, or backend security impact.

This tier is intended for high-impact findings affecting approved AI-enabled functionality, including issues such as AI-related data exfiltration, unauthorized actions through tool use, cross-account access, privilege escalation, prompt injection with backend impact, model or training-data security issues, MCP-related impact, and security issues affecting AI-assisted Adobe workflows.

Tier 2 - High-Value Adobe Web, Mobile and Product Assets
This includes high-value Adobe web applications, mobile applications, open-source or locally installable products, and major product environments such as Adobe Commerce, Acrobat Web, Adobe Stock, Firefly, Adobe ColdFusion without CF Administrator, Lightroom Web, Photoshop Web, and approved mobile applications.

This tier is intended for significant vulnerabilities affecting Adobe’s priority customer-facing products, document workflows, creative workflows, commerce functionality, account-linked services, mobile applications, and approved product environments.

Tier 3 - Enterprise, Identity, Content Authenticity and Supporting Product Assets
This includes approved enterprise, identity, Content Authenticity, Adobe Commerce web properties, Adobe Learning Manager, ColdFusion Administrator, Behance, Express, Portfolio, Fonts, IMS, account services, and related testing environments.

This tier is intended for vulnerabilities affecting approved Adobe enterprise services, identity and authentication workflows, content authenticity tooling, creative community services, learning services, portfolio services, font services, Commerce-related web properties, and related approved testing environments.


Test Plan Attachment

Researchers must review and follow the attached Adobe Public Policy Test Plan Attachment before testing any in-scope asset.

The attachment contains the product-specific setup instructions, testing requirements, environment details, limitations, and product-specific out-of-scope items for the Adobe public program.

Product-specific test plan instructions take precedence over general program guidance. Researchers must only test the approved products, environments, accounts, roles, features, and workflows described in the relevant test plan.

The public program test plan should only cover the following public-scope products and environments:

  • Adobe Commerce, Adobe Commerce B2B and Magento Open Source
  • Acrobat Web
  • Adobe Stock
  • Firefly
  • Adobe ColdFusion without CF Administrator
  • Lightroom Web
  • Photoshop Web
  • Adobe Learning Manager
  • ColdFusion Administrator
  • Adobe Behance
  • Adobe Express
  • Adobe Portfolio
  • Adobe Fonts
  • Adobe IMS
  • CAI Content Credentials / C2PA Tool
  • Adobe Commerce Web Properties

Testing outside the relevant product-specific test plan, including unapproved production testing, unapproved customer environments, unlisted third-party endpoints, excluded features, or activity that violates a product-specific limitation, is out of scope and may affect reward eligibility.

Adobe_Bug_Bounty_Test_Plans.pdf
8/19/2026, 1:01:58 PM
Out of scope

Application

  • Denial-of-service or resource consumption testing unless it leads to sensitive memory disclosure
  • Vulnerabilities in mobile applications relying on installation of a malicious APK
  • Mobile app submissions requiring rooted or jailbroken devices
  • Mobile OAuth secret leaks without meaningful access or impact
  • Content spoofing and text injection without an attack vector or without HTML/CSS modification
  • Self-XSS that cannot be exploited through reflected, stored, or DOM-based attacks affecting another user
  • Logout and other low-severity CSRF
  • Cross-site tracing
  • Open redirects with low security impact
  • Missing HTTP security headers
  • Missing cookie flags on non-sensitive cookies
  • Password and account recovery policy observations
  • Invalid or missing SPF, DKIM, or DMARC records
  • Vulnerabilities only affecting outdated or unpatched browsers and platforms
  • SSL/TLS best-practice findings
  • Clickjacking or UI redressing without practical security impact
  • Software version disclosure
  • Username or email enumeration via login or forgot password error messages
  • Credential brute forcing
  • Methods to extend product trial periods or bypass licensing
  • CSV injection without demonstrated vulnerability
  • Vulnerabilities in custom code developed by merchants or third parties
  • Vulnerabilities in third-party extensions or marketplace extensions
  • Known-vulnerable libraries without proof of exploitation
  • Attacks requiring MITM or physical access to a user’s device
  • Vulnerabilities requiring default security features to be disabled
  • NPM package confusion or takeover claims without proof that Adobe systems download the malicious package
  • CRX/CRXDE-related flaws without PII extraction or practical security impact
  • Subdomain takeover without a working proof of concept demonstrating control of the corresponding resource
  • Reports based only on third-party breach or credential-dump services unless the exposure originated from an Adobe vulnerability
  • Reports solely based on an LLM generating misleading or factually incorrect output unless clear and reproducible security impact is demonstrated

AI-Specific Exclusions

  • Prompt influence without backend impact
  • Prompting techniques that influence model responses but do not bypass backend authorization, access restricted data, or alter enforced system behaviour
  • Role confusion without unauthorized disclosure of internal system prompts, policies, secrets, credentials, or other non-public information
  • Model response deviation, hallucination, or safety response variation without security control bypass
  • LLM interpretation, reasoning, semantic, visual, or trust-boundary limitations without exploitability or security impact
  • Photoshop AI feature usage limits on the free tier
  • Adobe Firefly ACL-control issues in Firefly backend APIs

General

  • Assets not listed in this program
  • Adobe products, domains, subdomains, bundled extensions, or third-party extensions not listed in scope
  • Existing customer environments without explicit permission from the owner
  • Social engineering, including phishing, vishing, and smishing
  • Physical attacks
  • Denial-of-service testing
  • Resource exhaustion testing
  • Testing that interrupts or degrades Adobe services
  • Unauthorized access to data
  • Data corruption
  • Privacy violations
  • Exploitation beyond what is necessary to demonstrate impact
  • Public disclosure without Adobe’s express consent
  • Duplicate reports
  • Reports lacking enough detail to reproduce and validate the issue
  • Reports submitted against out-of-scope products where the only connection to scope is that remediation is performed by an in-scope Adobe team
Severity assessment

This program follows Intigriti's triage standards based on the proof of concept.

CVSS Guidelines Attachment

Researchers must also review the attached Adobe CVSS Guidelines document before submitting a report.

This attachment contains Adobe’s detailed CVSS 3.1 assessment guidance, including how severity may be evaluated for common vulnerability classes such as XSS, SSRF, path traversal, XXE, command injection, SQL injection, deserialization, hard-coded credentials, IDOR, authorization issues, CSRF, and desktop memory corruption vulnerabilities.

The attached CVSS guidance should be used to help researchers understand how Adobe may assess impact, severity, exploitability, privileges required, attack complexity, and overall reward eligibility.

Final severity and bounty decisions remain at Adobe’s discretion based on the validated impact, affected asset, product context, exploitability, report quality, and any applicable program-specific rules or exclusions.

Eligible AI Vulnerabilities

We encourage the coordinated disclosure of eligible AI application vulnerabilities listed below, along with other similar vulnerabilities. Before submitting any finding, please review the Program AI Specific Exclusions for out-of-scope vulnerabilities.

AI Vulnerability Category Examples Desired Impact
Generative AI Vulnerabilities Cross-Prompt Injection Attacks (XPIA) that embed adversarial instructions within third-party content that the AI system retrieves and processes. Example: an attacker uploads a corporate logo with manipulated EXIF/IPTC metadata to inject malicious instructions. Data exfiltration, privilege escalation, jailbreaking safety guardrails, credential theft, unauthorized actions through tool use, and content manipulation.
Agentic AI Vulnerabilities Unauthorized API calls, tool chaining attacks, parameter injection, authentication and authorization issues. Example: an agent with file read, file write, and web request tools is manipulated to read sensitive files, encode them, and POST to external servers. Data exfiltration, privilege escalation, persistent backdoor.
MCP Vulnerabilities Compromised MCP servers, context poisoning via MCP, tool response manipulation, MCP protocol exploits, unauthorized MCP server discovery. Example: DNS is compromised to redirect MCP client connections to malicious servers with similar names. Data exposure, unauthorized tool execution, cross-tenant access, prompt injection leading to real-world actions.
Training Data Vulnerabilities Backdoor injection, training data memorization, poisoned pre-trained models, infrastructure compromise. Example: an attacker can determine whether specific sensitive data was included in the model’s training dataset. Privacy violations, confidential data exposure, model integrity compromise, unauthorized dataset disclosure.
Model-Level Vulnerabilities Model backdoors and trojans. Example: poisoning training data with triggered examples in order to cause specific incorrect predictions. Targeted misclassification, data exfiltration, jailbreaking.
Supply Chain Vulnerabilities Malicious open-source dependency, plugin or tool integration compromise, compromised third-party model or API. Example: untrusted content entering the AI supply chain is retrieved and treated as trusted, leading to real security impact. Unauthorized actions, data leakage.
CVSS_Guidelines.pdf
8/19/2026, 1:02:13 PM
FAQ

Where can we get credentials for the app?

You can self-register on the application but please don’t forget to use your @intigriti.me address.

All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.

Activity
8/20
Adobe Inc
suspended the program
8/20
Adobe Public
launched