H1 HackerOne LIVE
Peloton
no bountyVDP
Open on HackerOne ↗
- listed
- before tracking
- tracked since
- 2026-09-20
- website
- http://onepeloton.com
- managed triage
- yes
- response efficiency
- 33%
- first response
- 2h avg
5 targets in scope
| asset | type | bounty | max sev | seen |
|---|---|---|---|---|
cms.onepeloton.com | domain | no | critical | 2026-09-20 |
cosmos-stage.onepeloton.com | domain | no | high | 2026-09-20 |
cosmos.onepeloton.com | domain | no | critical | 2026-09-20 |
qa1-cms.onepeloton.com | domain | no | high | 2026-09-20 |
www.onepeloton.com | domain | no | critical | 2026-09-20 |
1 out of scope — black ICE, don't touch
Security vulnerabilities that are identified in Peloton products or in website domains owned, operated, or controlled by Peloton that are not listed above are OOSother
Change log
get alerts ↗No changes since we started tracking on 2026-09-20.