I'm Juan Felipe Oz.

Offensive Security Engineer specialized in web application, API, and mobile penetration testing. Independent Vulnerability Researcher with disclosed CVEs in open source software, NASA recognition, and Burp Suite Champion. I build security tools, break enterprise systems, and publish what i find.

Experience

Offensive Security Engineer, NTT Data

June 2026 - Present (Remote, Colombia)

  • Adversarial testing across web, API, and mobile surfaces for enterprise clients throughout LATAM.
  • Embedded in CI/CD - assessing what ships before it becomes someone else's incident.

Offensive Security Consultant, KPMG

April 2025 - May 2026 (Bogotá, Colombia)

  • Penetration testing across regulated, high-stakes environments - finance, healthcare, energy.
  • Chained low-severity findings into critical impact, then translated it into risk executives act on.

Security Researcher, HackerOne / Bugcrowd

June 2023 – June 2026 (Remote)

  • Independent research acknowledged by Adobe, NASA VDP, and private programs.

Ethical Hacker - Siesa

January 2024 – June 2024

  • Security assessments on ERP and CRM platforms ahead of production release.

CVEs • Vulnerability Research

CVE-2026-14871

BOLA/IDOR in osTicket v1.18.3 and v1.17.7. Broken authorization let any authenticated user read tickets that weren't theirs to read.

advisory →

CVE-2026-35526

Denial of Service via unbounded WebSocket subscriptions in Strawberry GraphQL (+5M downloads/month on PyPI). An unauthenticated attacker can exhaust server resources by opening unlimited subscriptions without triggering any rate limit.

advisory →

CVE-2026-34406

Privilege Escalation via mass assignment of is_superuser in APTRS's user edit endpoint. A low-privileged authenticated user can escalate to superuser by sending a crafted request that modifies protected fields.

advisory →

CVE-2026-34381

Unauthenticated access to role-restricted documents in Admidio via a neutralized .htaccess file. File access controls were bypassable without any authentication.

advisory →

CVE-2026-34382

Missing CSRF protection on custom list deletion in Admidio's mylist_function.php. Allows an attacker to trick authenticated users into deleting arbitrary lists via a forged request.

advisory →

CVE-2025-50578

Host Header Injection + Open Redirect in the official Heimdall Docker image (LinuxServer.io). Manipulation of the Host header allows arbitrary redirection of authenticated users.

advisory →

CVE-2025-50579

Authentication bypass vulnerability in Nginx Proxy Manager v2.12.3. Reported via MITRE/NVD.

advisory →

More research in progress.

Some findings are under coordinated disclosure.

Achievements

BugCrowd Logo

Vulnerabilities reported and acknowledged in NASA's Vulnerability Disclosure Program.

NASA Letter of Appreciation 1

Letter of Appreciation - NASA VDP · May 15, 2025

NASA Letter of Appreciation 2

Letter of Appreciation - NASA VDP · May 29, 2025

HackerOne Logo

Adobe Security: Information disclosure of git metadata and Springboot actuator data, responsibly reported and resolved.

HackerOne Report

Disclosure of git metadata & Springboot actuator info · Adobe · HackerOne

Connect with me at