Security Vulnerability Reporting
The University of Cape Town Computer Security Incident Response Team, UCT CSIRT, welcomes reports of suspected security vulnerabilities affecting UCT systems, services, or digital infrastructure.
UCT does not currently operate a public bug bounty program or a formal vulnerability disclosure program. However, we appreciate responsible reports of valid security findings and will review submissions as capacity and risk require.
This page does not authorise security testing of UCT systems. If you are unsure whether an activity is permitted, please contact UCT CSIRT before proceeding.
How to report a vulnerability
Please email security vulnerability reports to:
Where possible, please include:
- The affected domain, system, application, IP address, or service.
- A clear description of the suspected vulnerability.
- Steps to reproduce the issue, using the least intrusive method possible.
- Evidence such as screenshots, timestamps, request/response examples, or logs.
- The potential impact, if known.
- Your contact details, should you wish us to follow up.
- Whether you believe the issue has been disclosed to anyone else.
Sensitive reports may be encrypted using the UCT CSIRT public PGP key published on the Contact us page.
What we ask of reporters
When reporting a suspected vulnerability, please:
- Act in good faith.
- Avoid accessing, modifying, deleting, copying, or exfiltrating data.
- Avoid privacy violations and do not disclose personal, student, staff, research, financial, or institutional information.
- Avoid disruption to UCT systems or services.
- Avoid denial-of-service testing, load testing, brute-force attacks, credential stuffing, phishing, social engineering, malware, physical attacks, or attempts to gain persistence.
- Stop testing immediately if you encounter sensitive data or service disruption.
- Give UCT a reasonable opportunity to investigate and respond before any public disclosure.
Scope
Reports may include suspected vulnerabilities affecting systems, domains, or services operated by or for the University of Cape Town, including systems under the uct.ac.za domain.
Reports involving third-party platforms, cloud services, suppliers, research collaborators, or federated services may need to be coordinated with the relevant service provider or responsible party.
What we may prioritise
UCT CSIRT is most likely to prioritise reports involving:
- Exposure of personal, student, staff, research, financial, or institutional data.
- Authentication or access-control weaknesses.
- Remote code execution or command execution.
- Privilege escalation.
- Publicly exposed administrative interfaces.
- Serious misconfigurations affecting confidentiality, integrity, or availability.
- Vulnerabilities that could materially affect UCT operations, users, or infrastructure.
Lower-risk findings, informational observations, automated scanner output without demonstrated impact, or issues affecting third-party services may receive a lower priority.
What to expect
UCT CSIRT will review valid reports and triage them according to risk, impact, affected constituency, and available operational capacity.
We may contact you for additional information. We may not be able to provide detailed remediation timelines, internal investigation details, or confirmation of every finding.
UCT does not offer monetary rewards, bounties, or compensation for vulnerability reports.
Public disclosure
Please do not publicly disclose vulnerability details until UCT has had a reasonable opportunity to investigate and, where appropriate, remediate or mitigate the issue.
If you intend to publish research or request acknowledgement, please raise this with UCT CSIRT as part of your report so that disclosure can be coordinated responsibly.
Incident reporting
If your report relates to an active cyber incident, compromised account, phishing campaign, malware infection, data breach, or ongoing threat activity, please report it to UCT CSIRT immediately using the same contact address.
Contact
UCT CSIRT
Email: uctcsirt@uct.ac.za
Website: https://csirt.uct.ac.za/