Meta Pays $78,000 Bounty for Flaw Exposing Customer Support Data
A security researcher received a $78,000 bounty from Meta after discovering a broken access control vulnerability that could have exposed sensitive customer support data.

Independent security researcher Rony K Roy has been awarded a substantial $78,000 bug bounty by Meta for uncovering a critical vulnerability within the company's customer support infrastructure. The flaw, initially reported in January 2026, was found to have a broader impact than first assessed, potentially exposing sensitive user information.
Roy's investigation revealed a chain of vulnerabilities including missing authorization, broken access control, and insecure direct object reference (IDOR) issues. When exploited together, these weaknesses could have allowed an attacker to enumerate Meta support case numbers and access the content of support requests. This could include email and chat conversations between users and Meta support staff, submitted files, and personal contact details shared during support interactions.
Beyond data exposure, the vulnerability also presented risks to the Meta Horizon Managed Solutions platform. An attacker could have potentially created support requests on behalf of organizations using the platform, altered support workflows, and added unauthorized individuals to existing support cases. Meta reportedly rolled out patches for the vulnerability in April 2026, and the company has stated it has found no evidence of malicious exploitation.
While Meta has not officially confirmed Roy's claims to SecurityWeek, the researcher is recognized on the company's bug bounty leaderboard for 2026, lending credibility to his report. The discovery highlights the ongoing challenges in securing complex backend systems that handle sensitive customer interactions.
This incident underscores the importance of robust bug bounty programs in identifying and mitigating security risks before they can be exploited by malicious actors. The significant payout reflects the potential severity of the discovered flaw and Meta's commitment to addressing such issues.
Roy's initial assessment focused on an authorization problem within Meta Horizon Managed Solutions, an enterprise tool for managing Meta Quest devices. However, his deeper analysis uncovered a more pervasive issue affecting Meta's broader backend support systems, demonstrating how seemingly isolated vulnerabilities can have far-reaching implications.
The successful identification and remediation of this vulnerability by an independent researcher serve as a testament to the value of external security audits. It also emphasizes the need for continuous vigilance and proactive security measures within large technology platforms that manage vast amounts of user data.
As companies increasingly rely on complex digital infrastructures, vulnerabilities like the one found by Roy can pose significant threats. The swift patching by Meta, coupled with the substantial bounty, indicates a serious approach to cybersecurity, aiming to protect both user data and the integrity of their support services.