Programs/Orbit Payments

Orbit Payments

PublicManaged triage
Payments infrastructure & merchant dashboard · orbit.io

Orbit Payments moves money for thousands of merchants, so anything touching authentication, authorization or settlement is treated as high impact. The public API and the merchant dashboard are both in scope.

Submit a report
Max bounty
$15,000
Avg. response
1.2 days
Reports resolved
204
Bounties paid
$483k
Researchers
63

Scope

In scope
api.orbit.ioAPI
dashboard.orbit.ioWeb
Webhook delivery serviceAPI
Merchant onboarding flowWeb
Out of scope
docs.orbit.io
Sandbox test cards & fixtures
Denial-of-service / volumetric
Rate-limit enumeration without impact

Rewards by severity

SeverityExamplesBounty
CriticalRCE, auth bypass, mass data exposure$6,000 – $15,000
HighSSRF, stored XSS, privilege escalation$2,200 – $5,600
MediumIDOR, CSRF on sensitive actions$560 – $1,400
LowReflected XSS, minor info disclosure$120 – $290

Rules & policy

01

Test only assets listed in scope. Never access, modify or delete data that does not belong to your test account.

02

Use your own test accounts. Stop immediately if you encounter another user's data and report it.

03

No denial-of-service, automated scanning at scale, or social engineering of staff or users.

04

Report each vulnerability once, with clear reproduction steps and evidence. Duplicates are closed against the earliest valid report.

05

Keep findings confidential until Orbit confirms a fix and agrees to disclosure. Good-faith research is authorized and will not be pursued legally.

Recent activity

HighSSRF via webhook URL validatorResolved · $3,000
MediumIDOR on /invoices/:id/exportAccepted
CriticalSettlement amount tampering on refund APIResolved · $15,000
LowMerchant ID disclosed in error responseResolved · $280

Found something on Orbit Payments?

Submit a structured report with steps and evidence. Managed triage reviews it, and a valid finding is rewarded by severity.

Submit a reportBack to programs