generated: '2026-08-17' method: searched probe: true source: https://documentation.ofelia.com/bonita/latest/contributing/vulnerability-reporting-policy summary: >- Bonitasoft/Ofelia publishes a real, named Vulnerability Reporting Policy inside the Bonita documentation, with a dedicated security contact, a coordinated disclosure timeline, and MITRE CVE coordination. It is NOT advertised at /.well-known/security.txt (RFC 9116) on any host, and there is no bug bounty. policy: - https://documentation.ofelia.com/bonita/latest/contributing/vulnerability-reporting-policy contact: - product-security@ofelia.com contact_note: >- The address moved with the June 2026 rebrand. Third-party writeups and older advisories cite bonitasecurity@bonitasoft.com; the current policy page names product-security@ofelia.com. Use the current one. process: reporting: >- Email the security team directly rather than disclosing publicly. A report should state the reporter's attribution preference (name, pseudonym or anonymous), a description of the suspected vulnerability, relevant source links, the affected components and versions, and the system environment. confidentiality: >- Vulnerabilities and associated findings are classified as confidential because they may compromise the integrity of other Bonita installations. disclosure_timeline: >- Once a fix ships across all maintained versions, subscription clients are notified in advance. Two weeks after the fix (excluding holidays) the release notes are updated publicly and the MITRE CVE entry is published. Community Edition users may have to wait for the next community release. cve_handling: >- The Ofelia Security Team coordinates CVE assignment with MITRE. Reporters may be credited in the release notes and in the MITRE report, though MITRE does not typically list reporters in the public CVE entry. scope: >- Bonita technical vulnerabilities only. The policy states explicitly that it "is not responsible for the whole security at Ofelia (infrastructures and ofelia.com website are the responsibility of the IT Team)" — so an infrastructure or website issue has no published intake path. bug_bounty: offered: false checked: '2026-08-17' evidence: - {url: 'https://hackerone.com/bonitasoft', status: 404} - {url: 'https://bugcrowd.com/bonitasoft', status: 404} safe_harbour: published: false note: >- No safe-harbour / authorized-testing statement appears in the policy. A researcher gets a confidentiality expectation and a credit path, but no legal assurance. security_txt: served: false checked: '2026-08-17' evidence: - {url: 'https://www.ofelia.com/.well-known/security.txt', status: 404} - {url: 'https://documentation.ofelia.com/.well-known/security.txt', status: 404} - {url: 'https://api-documentation.ofelia.com/.well-known/security.txt', status: 404} - {url: 'https://community.ofelia.com/.well-known/security.txt', status: 404} - {url: 'https://www.bonitasoft.com/.well-known/security.txt', status: 404} gap: >- This is the cheapest fix on the whole profile. The policy, the contact and the process all exist; publishing four lines at https://www.ofelia.com/.well-known/security.txt (Contact, Policy, Expires, Preferred-Languages) would make them machine-discoverable. NO SecurityTxt pointer is emitted because nothing is served. track_record: note: >- The policy is demonstrably exercised rather than decorative. Bonita 2026.2-u0 (2026-06-30) shipped two named security fixes with public CVE identifiers — CVE-2026-7307 (keycloak-saml-core, crafted XML) and CVE-2026-2575 (keycloak-saml-adapter-core, application-level DoS) — published in the release notes exactly as the policy describes. Bonita also has a long public CVE history (e.g. CVE-2022-25237, authorization bypass leading to RCE in Bonita Web 2021.2), which is what an actively researched open-source platform looks like. release_notes: https://documentation.ofelia.com/bonita/latest/release-notes hardening_docs: note: >- Distinct from disclosure, the product ships a documented hardening surface the vendor maintains: pages: - https://documentation.ofelia.com/bonita/latest/security/csrf-security - https://documentation.ofelia.com/bonita/latest/security/brute-force-login-protection - https://documentation.ofelia.com/bonita/latest/security/sanitizer-security - https://documentation.ofelia.com/bonita/latest/security/java-security-policy - https://documentation.ofelia.com/bonita/latest/security/enable-cors-in-tomcat-bundle - https://documentation.ofelia.com/bonita/latest/identity/rest-api-authorization - https://documentation.ofelia.com/cloud/latest/Security evidence: - {source: 'https://documentation.ofelia.com/bonita/latest/contributing/vulnerability-reporting-policy', kind: disclosure-policy, status: 200, checked: '2026-08-17'} - {source: 'https://documentation.ofelia.com/bonita/latest/release-notes', kind: cve-publication, status: 200, checked: '2026-08-17'}