
This could have been a short, straightforward blog post, but the United Nations Information Security team is incredibly strict when it comes to accepting reported vulnerabilities for responsible disclosure and Hall of Fame qualifications. Because of that, I’m going to include my actual journey of attempting to report multiple vulnerabilities. I first stumbled upon the existence of the United Nations Information Security Hall of Fame back in roughly October 2024.
I remember taking some time after Christmas 2025 to try and get my name onto the UN's Information Security Hall of Fame. Starting off with reconnaissance, I did some research and identified several domains belonging to the UN. Then, I enumerated their subdomains and manually checked them in a browser to see what they would reveal. Suddenly, I came across a subdomain belonging to unctad.org that triggered my instincts, telling me that something was off. I share the unredacted screenshots below which I used for my report to the UN.

As you can see on the bottom right of the Apache Solr screenshot above, it indicates that security was disabled for this server.


Clicking on the security tab, as seen in the next screenshot, proves that my instincts were right.



Similar unauthenticated public access to these Apache Solr admin panels was found for pre, qa, and dev, which represent different stages of the IT lifecycle. If you still do not think the severity is critical, take a look at the screenshot below.

By going to the Core Admin tab and clicking on a core, we can Unload, Rename, Swap, or Reload it. What are the implications, you ask? Anyone with malicious intent could have caused someone in UNCTAD's ICT Department to get fired. There was absolutely no security in place to prevent public access, meaning people with bad intentions could have easily deleted the database. I reported this finding to the UN on 30 December 2025 at 5:41 AM.

They replied with the email shown above on 30 December 2025 at 9:53 PM. I won't deny that I was eagerly waiting for the good news of being listed on their Hall of Fame for this critical-level vulnerability. After around two weeks of not receiving any updates, I noticed that the subdomains for the Apache Solr admin panels all suddenly returned an HTTP 404 Not Found error. Quickly, I emailed the UN Information Security team on 16 January 2026 at 10:48 AM to check on the status, since the subdomains could no longer be accessed publicly. However, I never received a reply from them, even up until now.
Honestly, I felt scammed. I had spent many hours on this finding and reported a critical vulnerability without tampering with their databases. However, seeing other names listed on the UN Information Security Hall of Fame reminded me that they were not simply scamming ethical hackers for free vulnerability reports. So, I decided not to give up just yet.
I decided to try again with a lower-impact vulnerability, which was a publicly accessible XML-RPC endpoint leading to Server-Side Request Forgery (SSRF). I reported this on 31 January 2026 at 11:37 AM, but the UN Information Security team rejected the submission. Okay, so now I could roughly gauge the kind of vulnerabilities they were willing to accept. Still, I could not give up, because when I want something, I always know I will get it. I continued my vulnerability hunt for days and weeks.
Suddenly, I came across a subdomain belonging to the UN Global Compact. I noticed a /s/ in its URL, which I knew was a telltale sign to test for a Salesforce misconfiguration. I tested it using a publicly available exploit, successfully leaked Personally Identifiable Information (PII), and reported my findings to UN Information Security. They replied with the following email.

Seriously? The UN Global Compact is not under the UN Secretariat? So, apparently, the only target scope they triage is the UN Secretariat. Considering that I had already exploited this vulnerability and leaked PII, I couldn't just let it go. I decided to find the person-in-charge at the UN Global Compact. After discussing it with Gemini, I decided to directly contact Anand Nair, the Head of Digital and IT at the UN Global Compact, on LinkedIn. However, I did not receive a reply. I then emailed the UN Global Compact's Integrity team on 27 February 2026 at 10:05 PM, explaining my intentions and asking for a secure communication channel. On 28 February 2026 at 2:55 AM, Courtney Moran, the Senior Manager of Integrity at the UN Global Compact, replied to my email.

After receiving her email, I misinterpreted it and assumed Anand would reach out to me in a separate email to provide a secure channel, such as a PGP public key for encrypted communication. Because of this, I waited a few days. But alas, no email arrived. When I reread the message, it turned out they expected me to reply directly to their email to explain my findings. I did so on 3 March 2026 at 11:50 AM. The next day, on 4 March 2026 at 6:28 AM, Anand replied with the following email.

It was a massive relief to safely and ethically report an exploited vulnerability on an out-of-scope target without having to face legal repercussions. But despite all this, our main mission was not yet accomplished. We still needed to find a unique vulnerability on actual UN Secretariat digital assets to secure a spot in their Information Security Hall of Fame. I needed a new strategy. Since I do not work there and do not know anyone at the UN, I had to approach this with systematic research and reconnaissance. I began researching what the UN Secretariat actually consists of and which offices its members belong to. Here is the UN's own link about the Secretariat, the United Nation system chart, and an unverified list of Secretariat members from uninnovation.network.
From the information gathered, I identified a proper list of target domains and enumerated their subdomains. I bookmarked several important findings, but I felt exhausted after spending months just trying to achieve a single entry in the UN Information Security Hall of Fame. Consequently, I changed my approach and relied on Google Dorking. It seems almost every ethical hacker wants to find Cross-Site Scripting (XSS), so I knew that even if I found an XSS vulnerability, there was a high chance it would be rejected as a duplicate. Then I remembered something. If I had previously found a misconfigured ArcGIS FeatureServer for UNICEF, I could possibly find a similar vulnerability within the UN's core digital assets. I used the Google Dork site:*.unocha.org inurl:rest inurl:services, and out came a bunch of promising results.

I will not bore you with the proof-of-concept details for this, as you can read about the exact same approach I used in my "Unauthenticated Uploads in UNICEF's ArcGIS FeatureServer" blog post.

I prepared my encrypted email report and sent it to the UN on 9 March 2026 at 1:50 PM. Later that night, at 11:43 PM, just as I was about to go to sleep, I received the following email from the UN.

The email instantly boosted my hope levels from 0% to 50%. After that, the UN Information Security team did not send any further email updates, so my hope remained at a cautious 50%. Then, on 20 May 2026, I randomly decided to check back on the United Nations Information Security Hall of Fame and noticed my name listed right there. Finally! I can officially move the United Nations to my hacked list and move on mentally to other organizations.
See you in the next hack.
@aaronamran
May 2026