Find the FLAG and win Intigriti swag! 🏆
This is a responsible disclosure program without bounties.
Rules:
This challenge runs from 24/06/2026 12:00 PM until 29/06/2026, 11:59 PM UTC.
- Out of all correct submissions, we will draw six winners on Tuesday 30/06/2026:
- Three randomly drawn correct submissions
- Three best write-ups
- Every winner gets an exclusive limited-edition t-shirt
- The winners will be announced on our X profile.
- For every 100 likes, we'll add a tip to announcement post.
- Join our Discord to discuss the challenge!
The solution:
- Should leverage a vulnerability on the challenge page.
- Shouldn't be self-XSS or related to MiTM attacks.
- Should require no user interaction.
- Should require no bruteforcing (if you have to, keep requests below 1 req/sec).
- Should include:
- The flag in the format
INTIGRITI{.*} - The payload(s) used
- Steps to solve (short description / bullet points)
- The flag in the format
- Should be reported on the Intigriti platform.
Get started:
- Repeat your attack against the challenge server!
N/A
This program follows Intigriti's triage standards based on the proof of concept.
N/A
For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.
It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.



























