Bitrix24 Vulnerability Disclosure Policy

Effective on: August 6, 2026

The security of Bitrix24 users is of paramount importance to us. We place particular emphasis on ensuring the security of the products we develop, including vulnerability detection during the development and testing lifecycle. We also welcome the responsible disclosure of any vulnerabilities identified by external researchers. We can process reports on a confidential and anonymous basis upon the researcher's request.

We define a security vulnerability as an unintentional weakness that could be exploited to compromise the integrity, confidentiality, or availability of our products. If you believe you have discovered a vulnerability, please submit a report to our security team.

1. How to Report a Vulnerability
You may report a discovered vulnerability through one of the following channels:

To avoid duplication, please use only one reporting channel per submission. We will acknowledge receipt of each report within 48 hours, conduct a thorough investigation, and take all appropriate corrective measures to remediate the identified vulnerability.

2. Scope
This Vulnerability Disclosure Policy applies to all Bitrix24 products placed on the European Union market as Products with Digital Elements, including:

  • Bitrix24 Cloud (SaaS);
  • Bitrix24 On-Premise / Self-Hosted (including updates and distribution packages);
  • Bitrix24 Mobile & Desktop Applications;
  • Bitrix24 API and official integrations;
  • Products listed on the Bitrix24 Marketplace (developed by Bitrix24).

3. Out of Scope
The following are outside the scope of this Policy:

  • Reports generated solely by automated scanners without manual validation and proof of exploitability;
  • Self-XSS vulnerabilities (exploitable only by the submitting user themselves);
  • Denial-of-Service (DoS/DDoS) testing;
  • Absence of rate limiting as a standalone finding without demonstrated security impact;
  • Vulnerabilities in third-party products or libraries not directly controlled by Bitrix24;
  • Reports lacking a working Proof-of-Concept (PoC).

4. Report Contents
A well-structured report enables our security team to efficiently reproduce, validate, and remediate the reported issue. Please include the following information:

  • A detailed description of the vulnerability and its potential impact;
  • The vulnerability category as classified under Common Weakness Enumeration (CWE);
  • The affected product and version in which the vulnerability was identified;
  • Steps to reproduce the vulnerability (Proof-of-Concept), including video recordings, screenshots, payloads, and web/API requests and responses;
  • Recommended remediation steps, where applicable.

5. Remediation Timelines
Each confirmed vulnerability is logged as a separate ticket in our issue tracking system and assigned to the relevant development team for remediation, followed by testing and fix verification. Upon confirmation of exploitability, Bitrix24 commits to releasing a fix or compensating controls within the following timeframes:

  • Critical severity vulnerabilities — within 5 business days;
  • High severity vulnerabilities — within 14 business days;
  • Medium and Low severity vulnerabilities — within the next scheduled release cycle.
These timelines represent target commitments and may be adjusted based on the nature, complexity, and potential impact of a given vulnerability.

6. Researcher Guidelines
We respect all security researchers and are grateful for your contribution to the safety of Bitrix24 users. In conducting your research, please adhere to the following rules:

  • Do not compromise the privacy of other Bitrix24 users or access data beyond what is strictly necessary to demonstrate the vulnerability;
  • Do not impair the availability of Bitrix24 services (e.g., by conducting Denial-of-Service attacks);
  • Do not destroy or disclose data accessed during the course of your research;
  • If multiple security issues are identified, submit a separate report for each vulnerability. If the attack involves a chain of sequentially exploited vulnerabilities, submit a single report with a detailed description of the dependencies;
  • Do not exploit the discovered vulnerability for personal gain or disclose information about it to third parties;
  • Do not conduct social engineering attacks or spam campaigns targeting Bitrix24 users or employees;
  • Do not attempt physical interference with Bitrix24 employees, property, or data centres;
  • Do not submit reports generated solely by automated scanners without manual validation.

7. Coordinated Disclosure
We ask researchers not to publicly disclose information about a discovered vulnerability, or share it with third parties, prior to the release of an official fix (patch) or without prior written authorisation from the Bitrix24 security team.

Responsible, coordinated disclosure gives us the opportunity to investigate the issue, develop and test a solution, and help protect all Bitrix24 users before technical details become publicly available.

Bitrix24 publishes Security Advisories containing information about resolved vulnerabilities and recommendations for remediation.

8. Safe Harbor
We recognise the importance of the work carried out by security researchers and are committed to maintaining a constructive relationship. Bitrix24 will not initiate legal action against you provided that you:

  • act in good faith;
  • comply with the requirements of this Policy;
  • do not take actions intended to cause harm to Bitrix24 products or users.

9. Regulatory Reporting Obligations (Cyber Resilience Act)
In accordance with Article 14 of Regulation (EU) 2024/2847 (Cyber Resilience Act), upon identification of an actively exploited vulnerability or a serious security incident affecting the security of our products, Bitrix24 will submit notifications via the Single Reporting Platform, ensuring simultaneous notification of ENISA and the competent national CSIRT, within the following timeframes:

  • Early warning notification — within 24 hours of becoming aware of the incident;
  • Detailed technical notification — within 72 hours;
  • Final report — no later than 14 days after the release of a fix.
These obligations apply from 11 September 2026.

By submitting a report, you confirm that you have read and agree to the terms of this Policy.