Citadel
System boundaries / enterprise services
This page records only information safe for public release. It does not expose active hypotheses, report details or unpatched behavior.
System boundaries / enterprise services
Access boundaries / analysis workflows
Runtime behavior / application resilience
A critical multi-stage chain with system-level impact was reported. Technical details remain restricted during coordinated disclosure.
A high-severity multi-stage chain resulting in restricted file disclosure was reported. Technical details remain restricted during coordinated disclosure.
A medium-severity availability issue reachable by an ordinary authenticated user was reported. Technical details remain restricted during coordinated disclosure.
A high-severity server availability issue reachable without authentication was reported. Technical details remain restricted during coordinated disclosure.
A medium-severity access-control issue exposing restricted analysis data was reported. Technical details remain restricted during coordinated disclosure.
A medium-severity access-control issue exposing protected server-rendered content without authentication was reported. Technical details remain restricted during coordinated disclosure.
A medium-severity CI/CD integrity issue affecting a protected deployment workflow was reported. Technical details remain restricted during coordinated disclosure.
A medium-severity cross-boundary CI/CD trust issue affecting protected jobs was reported. Technical details remain restricted during coordinated disclosure.
Titles describe only the broad impact area without naming affected products or exposing reproduction details.
12 public entries / latest first
Active research under Acheron has ended. The operation now awaits program results and coordinated disclosure outcomes while the next operation is planned.
The Citadel file-disclosure chain and application-layer denial-of-service report advanced to program review. Technical details remain restricted while assessment continues.
The Bastion front produced a medium-severity cross-boundary CI/CD trust issue affecting protected jobs. Technical details remain restricted during coordinated disclosure.
The Bastion front produced a medium-severity CI/CD integrity issue affecting a protected deployment workflow. Technical details remain restricted during coordinated disclosure.
The Citadel server compromise chain was marked as a duplicate. Publication of Vyntra's exploit variant and technical writeup will wait until the original issue is patched.
The Citadel front produced a critical multi-stage server compromise chain with system-level impact. Technical details remain restricted during coordinated disclosure.
The Citadel front produced a medium-severity application-layer denial-of-service issue reachable by an ordinary authenticated user. Technical details remain restricted during coordinated disclosure.
The Vanguard front produced a high-severity server out-of-memory issue reachable without authentication. Technical details remain restricted during coordinated disclosure.
The Citadel front produced a high-severity multi-stage SSRF chain resulting in restricted file disclosure. Technical details remain restricted during coordinated disclosure.
The Bastion front produced a medium-severity access-control issue exposing restricted analysis data without authentication. Technical details remain restricted during coordinated disclosure.
The Vanguard front produced a medium-severity access-control issue exposing protected server-rendered content without authentication. Technical details remain restricted during coordinated disclosure.
The scope and research heuristics were defined, and construction of the Proteus research corpus began under operation identifier OP-001.
Public CVEs, advisories and writeups will be linked here after disclosure.
VYNTRA RESEARCH