root@nftp:~$/posts/2026-10-06/the-quiet-patch
2026-10-06IDORPATCHED

One Vendor, $100, and a Breach That Reached Every School That Trusted Them

How a routine graduation photo platform exposed student data across Ontario and Quebec, and what it took to get a response.

I uncovered a serious security flaw in a graduation photo company's platform. It could expose personal student data at every university and college that uses them across Ontario and Quebec. I reported it the right way. For three months, they didn't answer a single email, call, or voicemail. After I escalated to the universities, they fixed it quietly — and paid me $100.

Here's the part that should actually worry you: I have no idea how long that door was open before I found it, or who else walked through it first.

How I found it

In April 2026, I graduated from a university in Ontario. Like thousands of students, my grad photos went through a third-party vendor.

While using their platform, I found a broken access control vulnerability — one that could let a user view another user's personal data instead of their own.

The information exposed included:

This wasn't a theoretical bug. It was a live door into the personal records of students at multiple colleges and universities, across two provinces — and there was nothing stopping anyone who found it from walking through, before me, after me, or instead of me.

I tested only the minimum necessary to confirm it was real. No enumeration, no bulk extraction, no retained data. Then I reported it responsibly and gave the company every chance to fix it quietly and professionally.

The technical root cause, for those who want to know: this was a broken access control / insecure direct object reference (IDOR) issue, one of the most common and well-documented vulnerability classes in web applications. In short, the platform determined which user's data to return based on a client-supplied value, rather than properly verifying server-side whether the requesting session was actually authorized to view that specific user's record. That gap was enough to retrieve another user's profile data.

How it worked, at a high level: the profile endpoint identified "which account am I serving" using a client-supplied identifier sent back on every request, rather than deriving that from a server-validated, authenticated session. Change the identifier, and the server handed back a different user's record — no ownership check in between. This is the textbook shape of an IDOR: the server trusts the client to say who it's asking for, instead of checking who it's actually talking to.

The three months of silence

Here's what "responsibly" got me:

Three months. A vulnerability sitting wide open on a platform handling the personal data of students at institutions across two provinces. And the company responsible for protecting it did not respond to a single email, call, or voicemail.

Email #1 · Initial disclosure
from
Me
to
Vendor Team
date
Jun 3, 2026 · 8:00 AM
Hello Vendor Team, I’m writing to responsibly disclose a security vulnerability affecting your platform: [REDACTED — vendor platform URL] Summary I identified an access control vulnerability that may allow unauthorized access to user accounts and associated personal information. Potential Impact Based on limited testing, it appears possible to access information belonging to other users by modifying certain request parameters and session context. The exposed information may include: - Full name - Email address - Phone number - Home address - Graduation photos - Institution Attended - Payment Receipts Based on observed behavior, the issue appears capable of affecting users across multiple universities and colleges in Ontario and Quebec and may potentially expose personal information belonging to a significant number of students. Validation I confirmed the issue using only minimal testing necessary to verify the vulnerability. No data was modified, retained, or extracted beyond what was required for confirmation. Technical Details To minimize unnecessary exposure risk, I have intentionally not included detailed reproduction steps in this initial email. I would be happy to provide additional technical details, affected requests, proof-of-concept information, or a walkthrough through. If preferred, I would also be available for a short meeting or call with the appropriate technical/security contact to demonstrate and explain the issue directly. Disclosure I have not publicly disclosed this issue and am reporting it in good faith to help protect affected users and improve platform security. I intend to follow a coordinated disclosure process and would appreciate the opportunity to work with your team on remediation before discussing the issue publicly. Please let me know if you have a vulnerability disclosure policy, security contact, or safe harbor policy that governs vulnerability reporting. Unless otherwise agreed upon, I generally follow a 90-day coordinated disclosure timeline. If the issue remains unresolved after that period, or if I do not receive a response despite reasonable attempts to establish communication, I may consider limited public disclosure of the vulnerability details in a manner intended to promote remediation and protect affected users. I remain willing to discuss reasonable extensions where active remediation efforts are underway. As a suggested timeline, I would appreciate an acknowledgment of receipt within 7 days and an update regarding remediation efforts within 90 days, although I am willing to discuss reasonable adjustments based on the complexity of the fix. Please let me know the appropriate contact and next steps. I would be happy to assist with validation, testing, or clarification as needed. Thank you for your time and attention. Best regards, REDACTED
Email #2 · Follow-up
from
Me
to
Vendor Team
date
Jun 10, 2026 · 1:09 PM
Hello Vendor Team, I'm following up regarding the security vulnerability disclosure I sent on Jun 3, 2026, 8:00 AM concerning a potential access control issue affecting user account data on your platform. I wanted to confirm that my report was received and ask whether there is an appropriate security or technical contact I should coordinate with regarding this issue. As noted in my original message, I have not publicly disclosed the vulnerability and am happy to provide additional technical details, proof-of-concept information, affected requests, or a live walkthrough to assist with validation and remediation. Given the potential exposure of student personal information, I would appreciate an acknowledgment of receipt when possible. Thank you again for your time and attention. I look forward to working with your team toward responsible remediation. Best regards, REDACTED
Email #3 · Final warning
from
Me
to
Vendor Team
date
Sep 8, 2026 · 10:19 AM
Hello Vendor Team, I am writing a third time regarding the critical access control vulnerability I reported on June 3, 2026, which exposes the sensitive personal information of students across multiple universities and colleges in Ontario and Quebec. To date, I have sent two detailed emails and left a voicemail, but I have not received a human response or any actual communication regarding the status of this report. While I did receive an automated email receipt, this does not constitute an acknowledgment of the vulnerability itself or provide a point of contact for remediation. Given the severity of the exposed data, which includes home addresses, phone numbers, and payment receipts, and the total lack of meaningful communication from your team, I must reassess my disclosure strategy to ensure these students are protected. If I do not receive a direct, human acknowledgment of this report and a point of contact for your technical or security team by September 15, 2026, I will have no choice but to directly contact the IT security and privacy compliance teams at the affected universities and colleges. My goal in doing so is not to cause disruption, but to ensure that the institutions whose students are actively exposed to this risk are made aware so they can take appropriate steps to protect their communities, given that your platform is not responding to direct security reports. I want to be clear: I am still entirely willing to keep this within a coordinated, private disclosure with your team. I can provide a brief walkthrough of the issue, help your developers validate the flaw, and work with you on a fix before any external parties are notified. All I need is a reply from an actual team member confirming you received this and a willingness to engage. I hope we can resolve this quickly and quietly. Best regards, REDACTED

Going to the universities

At that point, I had a choice: keep waiting, or make sure the institutions whose students were actually at risk knew what was going on. I chose the latter — not to cause a scene, but because the students actually at risk deserved to know their vendor wasn't responding to a legitimate security warning about their own data.

Notice to universities
from
Me
to
Security / Privacy Team · REDACTED University
date
Sep 21, 2026 · 3:13 PM
Hello Security/Privacy Team, I am contacting you directly regarding a potential security vulnerability involving the vendor, a third-party graduation photography provider used by multiple universities and colleges across Ontario and Quebec. I am an alumni at REDACTED University and graduated in (April 2026). During the graduation process, I became familiar with the platform used for graduation photographs. While interacting with the platform, I identified what appears to be an access-control vulnerability that may allow unauthorized access to information associated with other users. After discovering the issue and observing the type of information that could potentially be accessed, I became concerned about the privacy and security implications for students. As a result of these concerns, I ultimately chose not to have my graduation photograph taken through the platform. I am contacting the universities because the vendor is publicly used by multiple universities and colleges across Ontario and Quebec. The vendor's relationships with participating institutions are publicly identifiable, and the issue I identified exists at the vendor's platform level. Potentially Exposed Information Based on my limited testing, the access-control issue may allow a user to access information associated with other users without appropriate authorization. The information I observed as potentially accessible includes: - Full name - Email address - Phone number - Full Home address - Graduation photographs - Institution attended - Payment receipts The combination of this information could represent a significant privacy concern for affected students. I want to emphasize that I deliberately limited my testing. I did not attempt to systematically enumerate students, download large quantities of information, modify records, or retain personal information beyond what was necessary to establish that the access-control issue existed. My Disclosure Attempts to the vendor Before contacting institutions directly, I attempted to report the vulnerability to the vendor and give them an opportunity to investigate and remediate the issue privately. My communications were sent on the following dates: - June 3, 2026 at 8:00 AM - Initial vulnerability disclosure - June 10, 2026 at 1:09 PM - Follow-up requesting acknowledgment and an appropriate security or technical contact - September 8, 2026 at 10:19 AM - Third communication requesting engagement regarding the unresolved vulnerability I also tried to call the vendor numerous times and left a voicemail during my attempts to establish communication. The vendor's system provided an automated email receipt, but I have not received a substantive response from a security or technical representative or been provided with a point of contact through which the vulnerability can be investigated and remediated. In my communications, I made it clear that I was willing to provide additional technical information, affected requests, proof-of-concept information, or a private walkthrough to assist with validation and remediation. I have not publicly disclosed the vulnerability or released any student information. I believe it is important that potentially affected institutions be made aware of the issue, particularly given the nature of the information that may be accessible. My intention is not to create unnecessary disruption. My goal is to ensure that potentially affected students are protected and that the underlying vulnerability receives appropriate investigation and remediation. I am also willing to coordinate directly with Information Security, Privacy, IT, or incident-response personnel. Request for Confirmation Please confirm receipt of this notification and, if possible, provide the appropriate contact within your Information Security, Privacy, or IT Incident Response team who can coordinate with me regarding this matter. I would prefer to provide the technical details directly to an authorized security contact rather than include potentially sensitive information in this initial email. I am making this disclosure in good faith and have attempted to work with the vendor privately before contacting potentially affected institutions. I remain willing to coordinate with the vendor and the universities toward responsible investigation and remediation. Thank you for taking the time to review this matter. Regards, REDACTED

That's what worked. Two days after university security teams received my email, the CEO reached out personally — explaining that my reports had apparently been sitting in a spam/deleted folder the entire time.

CEO reply #1
from
Vendor · CEO
to
Me
date
Sep 24, 2026 · 8:16 AM
Hi REDACTED, We received an email from REDACTED yesterday detailing your concerns. Thank you for bringing this to our attention. I am very sorry for not responding earlier; however, my customer service team found these emails in our deleted folder, as they were likely originally received as SPAM. That being said, I would like to speak with you ASAP to go over all of your concerns and ensure we are doing everything we can from a privacy and security point of view. Please let me know when works best for you. Thanks, REDACTED

The quiet fix

We began arranging a call so I could demonstrate the issue directly, with written terms covering good-faith treatment, authorization, data handling, and confidentiality — standard practice in vulnerability coordination.

Me ➜ CEO · call terms
from
Me
to
Vendor · CEO
date
Sep 24, 2026 · 1:25 PM
Hello REDACTED, I appreciate you reaching out personally. I'm available September 25, 26, 27 2026. A video call with screen sharing works best, so you can see the issue firsthand. Before we meet, I'd like to confirm the following points in writing, as is standard practice in vulnerability coordination. I want to be fully transparent about what the demonstration involves: 1. Good-faith treatment. My original report and the limited testing behind it are acknowledged as good-faith security research, and no legal action will be taken against me in connection with the report or the demonstration described below. 2. Authorization for the demonstration. You authorize me to demonstrate the vulnerability live during our call. To be fully transparent: this demonstration will involve accessing real user accounts on your platform. I will keep this strictly limited to the minimum necessary to demonstrate the issue, I will not modify any data, and I will not download, export, save, or capture anything during the demonstration. 3. Data handling. I do not retain any personal information from your platform, and I will not retain any as a result of this process. 4. Confidentiality. The technical details of the vulnerability will remain confidential between us (and any institutions you choose to involve) until remediation is complete. If these points are acceptable, a brief reply confirming them is all I need, and we can schedule the call at your earliest convenience. Best regards, REDACTED
CEO reply #2
from
Vendor · CEO
to
Me
date
Sep 24, 2026 · 5:21 PM
Hi REDACTED, Thank you for sending those dates. I am thinking I should involve my IT team in the meeting. Let me speak with them and get back to you to find a date that works for everyone. Thanks, REDACTED
Me ➜ CEO
from
Me
to
Vendor · CEO
date
Sep 24, 2026 · 6:03 PM
Hello REDACTED, Sounds good, please keep me posted. Best regards, REDACTED

Before that call ever happened, the vulnerability was patched — quietly, over a weekend. No notice to me. No notice, as far as I know, to the universities I'd warned. No explanation of how long it had been live. No audit of who may have accessed it. Nothing.

I followed up to ask for an update. The CEO still didn't mention the fix was already live:

Me ➜ CEO · check-in
from
Me
to
Vendor · CEO
date
Sep 30, 2026 · 1:57 PM
Hello REDACTED, I wanted to follow up, as I haven't heard back from you since the last email. I wanted to check in and see if there were any updates regarding the meeting. Best regards, REDACTED
CEO reply #3
from
Vendor · CEO
to
Me
date
Oct 2, 2026 · 1:50 PM
Hi REDACTED, Hi, so sorry. One of my IT guys was unavailable earlier this week. Let me re-connect with them and get back to you. Thanks, REDACTED
Me ➜ CEO · fix noticed
from
Me
to
Vendor · CEO
date
Oct 5, 2026 · 8:00 AM
Hello REDACTED, It appears that the vulnerability has now been remediated, as the behavior I originally identified and reported no longer appears to be present. I am glad to see that the issue has been addressed. I was, however, surprised that the issue appears to have been remediated without any communication or acknowledgment to me, particularly given my repeated attempts over the past several months to report the vulnerability responsibly and work with the vendor privately. As the researcher who identified and reported the vulnerability, I would like to discuss formal recognition of the disclosure, including whether the vendor offers any form of researcher acknowledgment or reward for responsible security reports. Please let me know what your process is for recognizing security researchers who report vulnerabilities to your organization. Best regards, REDACTED

I've since independently verified that the fix is in place. That part is genuinely good news.

But let's be clear about what we still don't know: nobody — not me, not the universities, and, based on what they've told me, not even the vendor — knows how long this was exploitable, or whether someone with far less restraint than me already has that data sitting in a folder somewhere. Without an audit, that question stays open.

The reward

When I asked what their process was for recognizing security researchers who report vulnerabilities in good faith, this is the reply I got:

CEO reply #4 · the reward
from
Vendor · CEO
to
Me
date
Oct 5, 2026 · 11:26 AM
Hi REDACTED, We appreciate your efforts. We have etransferred you $100. Thanks, REDACTED

For a flaw affecting student data across two provinces, reported responsibly, and unresolved for over three months.

Why this matters beyond me

This isn't really about me, or about $100. It's about:

I followed the disclosure process I outlined from the start. The fix came after the universities were contacted, three-plus months after my first report.

Students trusted this platform with their personal information. I hope this account helps other researchers and institutions think about how disclosures like this one get handled.


Timeline of events referenced in this post is based on my own email records. Screenshots and correspondence above have been redacted to remove personally identifying information not relevant to the public interest in this disclosure.

CyberSecurityDataPrivacyResponsibleDisclosureInfoSecStudentPrivacyOntarioQuebecIDORBugBountyVulnerabilityDisclosureWebSecurityPrivacy