Early access: the directory is still filling out, and every rating here is a reported experience.
← The brief
Published finding · Bugcrowd

Comcast Xfinity Bug Bounty A finding accepted against *.comcast.com. Bugcrowd published no award figure for it.

low unresolved
01 · The record

Everything Bugcrowd published about this

Programme
Comcast Xfinity Bug Bounty In our directory, so it has reviews and a grade.
Platform handle
comcast-mbb
Asset
*.comcast.com The specific asset the finding landed against, as the platform named it.
Severity
low Bugcrowd rates P1–P5; this is that rating in HackerOne's words so the two feeds can sit in one table.
Award
Not published This does not mean nothing was paid. Both platforms let a programme accept a finding without publishing the figure, and most do.
Found by
Withheld The platform did not publish a name. We store that as withheld and never guess.
State
unresolved — accepted, not yet fixed
Accepted
6 July 2026 3 months ago. This is the date the programme accepted the finding.
First seen here
16 August 2026 When our sweep first read this entry. It says nothing about the finding, only about us.
Platform reference
f1f4e8f1-1463-44c5-9c1b-de5860321bf8
View the programme on Bugcrowd ↗ Bugcrowd publishes the acceptance, not the submission. There is no public write-up for this finding anywhere, and no page for the entry itself, so this link goes to the programme. Everything Bugcrowd did publish about it is already above.
03 · The programme

What else Comcast Xfinity Bug Bounty has published

See Comcast Xfinity Bug Bounty's grade and researcher reviews →

Where this came from. One row of a public platform feed, stored as published and never edited. We hold no report title, no write-up and no reproduction steps, because the feeds do not carry them and we do not go looking for them. A withheld name stays withheld; if a finder later asks the platform to un-name them, the next sweep un-names them here. Absence of an award figure is publication policy, not evidence a programme did not pay.