# OpenAI patches SSO flaw after researchers reach internal repository

_Published Saturday, September 19, 2026 at 5:05 AM EDT · Security, AI · Latest · Tier 2 — Notable_

![OpenAI patches SSO flaw after researchers reach internal repository — Primary](https://media.thenextweb.com/2026/09/claude-chatgpt-app-icons-iphone.jpg)

Hacktron AI researchers said they chained a third-party forum image-upload flaw with a session-token configuration error to access OpenAI employee accounts and an internal code repository. The team privately disclosed the issues after reaching access in under 72 hours, and OpenAI patched the single sign-on weakness about 14 hours later. The researchers received a $6,500 payment. The source says neither weakness was an AI vulnerability, though Claude was used in the research process.

## Sources

- [The Next Web](https://thenextweb.com/news/hacktron-claude-openai-bug-bounty-6500-guardrails-paper)

---
Canonical: https://techandbusiness.org/newswire/rmje5hNvnAzuvMpn2d3JOH
Published: 2026-09-19T09:05:45.142Z
Story chronology: 2026-09-19T06:27:52.000Z
Retrieved: 2026-09-19T10:47:57.836Z
Publisher: Tech & Business (techandbusiness.org)
