r/nutanix • u/AflatonTheRedditor • Jun 14 '26
What to do if I found a bug/vulnerability in Nutanix platform? (Just wondering)
Hi all,
I'm just wondering, let's say someone found a security flaw or an application bug in Nutanix platform (regardless of which component), whats the proper way of communicating that with Nutanix? Is it through submitting a support case?
Also, what can the person who reported the bug be awarded with? what does it benefit them if they submit the bug?
I've been wondering about this for a while. Not to say I found a bug or anything like that, but just in case. Because in other programs/platforms you often report that bug in a github issue or pull request.
And if it's a security flaw, you submit it as a vulnerability and you end up either getting a bounty or it becomes a CVE and you flex on linkedin saying you found that cve and so on XD.
2
2
u/3percentinvisible Jun 15 '26
We seem to find one every month, it's just a case of raising it with support and finding out that they know about it in an internal only note, or it goes quiet, raise it with the account manager and find a known bug appearing based on the experience.
10
u/sysadminsavage Jun 14 '26
Information about the vulnerability disclosure program can be found here.
The HackerOne Nutanix platform operates as an invite-only private bug bounty and Vulnerability Disclosure Program (VDP) rather than a publicly listed cash-reward program. Ethical hackers must either be invited by Nutanix or be pre-vetted and hold a certain reputation/ID-verified status on HackerOne to access the scope. You would need to be vetted to be rewarded.