How the Cookie Crumbled — Write Up

This “baby’s first” write-up covers my first public vulnerability discovery, In July 2026 on a third party service vendor platform (“The Vendor”). Identifying information has been substituted for privacy.

People involved

Discovery team: Me (coordination, write-up, disclosure), Trent (initial discovery and notification), Ajay (technical investigation and reproduction) and Finn (vetting, verification and support)

Vendor / platform staff: anonymised — referred to below by role only (Technical Lead, initial contact)

University staff: anonymised — referred to below by role only

Incident Summary

Roughly midday in late July an event registration opened on The Vendor’s website, A sudden spike in concurrent logins triggered a caching error that caused one team member to be logged into the account of an uninvolved, unrelated user. Having accidentally gained access to this account, the team began a proper investigation. The vulnerability was patched roughly four hours after discovery and two hours after the Vendor was notified. The affected account holder is referred to below as “the affected user”

Vulnerability findings

Steps to reproduce

A few takeaways from running this disclosure:

Open the slides directly (PDF) — more reliable on mobile, where embedded PDF viewers can be flaky.