October 10, 2026
Finding an Exposed Admin Panel on a Government Portal: A Responsible Disclosure Story
As part of my ongoing practice as a SOC L1 trainee, I regularly do passive reconnaissance on publicly accessible websites β not to exploitβ¦

By Byteshubhx
2 min read
As part of my ongoing practice as a SOC L1 trainee, I regularly do passive reconnaissance on publicly accessible websites β not to exploit anything, but to understand how real-world misconfigurations show up outside of lab environments. This is one of those findings.
The Setup
I was running basic recon techniques β search engine dorking, directory/path enumeration patterns β against a category of websites that are notoriously under-resourced from a security standpoint: municipal/government portals. These sites are often built by third-party vendors, deployed once, and rarely revisited for security hardening after launch.
During this process, I came across a portal where the admin login panel was directly reachable from the homepage β no obscurity, no path restriction, nothing hiding it. That alone isn't a vulnerability. What made it one was what came next.
The Finding
Out of curiosity (and because this is a textbook SOC/pentest checklist item), I tested whether the panel was still running on default vendor credentials. It was.
Two things compounded the severity:
- No rate limiting on the login form β meaning even if credentials weren't default, the panel would have been trivially brute-forceable.
- Default credentials still active β suggesting the portal had either never been hardened post-deployment, or credential rotation simply wasn't part of the maintenance process.
I did not log in beyond confirming access was possible. No data was viewed, modified, exported, or deleted. The moment I confirmed the issue existed, I stopped.
What I Did Next
This is the part that actually matters more than the finding itself:
- No further interaction with the panel once the vulnerability was confirmed.
- Identified the right disclosure channel β tracked down an official contact for the authority running the portal.
- Reported it on 01/10/2026 via email, with a clear, non-technical summary of the risk (exposed admin access, default credentials, no rate limiting) and an offer to provide more detail if needed.
- Attempted a follow-up call to make sure the report didn't get lost in a generic inbox.
- As of writing this, I haven't received a response.
That last point is common, and it's worth normalizing for anyone starting out in this space β most independent disclosures to under-resourced orgs go unanswered or take weeks. The professional move is persistence through proper channels, not escalation through public pressure, and definitely not continued access to "test" further.
Why This Matters for Defenders
This is where I want to pivot β because the point of sharing this isn't "look what I found," it's "look what SOC/blue teams should be catching before someone less well-intentioned finds it."
A few takeaways if you're on the defensive side:
- Default credentials are still one of the most common real-world findings, even in 2026, even on government infrastructure. CIS benchmarks and vendor hardening guides exist precisely because post-deployment credential rotation is so often skipped.
- Rate limiting on auth endpoints isn't optional. Its absence turns a weak-password problem into a guaranteed compromise, whether through credential stuffing, brute force, or (as here) a default login nobody changed.
- Exposed admin panels on the homepage are a design smell. Even with strong auth behind it, unauthenticated visibility of an admin login invites targeted attacks. IP allowlisting, VPN-gated access, or at minimum path obscurity reduces the attack surface significantly.
- Vendor-deployed government portals need a security handoff checklist. A lot of this risk traces back to a vendor shipping a product and no one on the receiving end owning security post-launch.
Closing Thought
I'm sharing this not to call anyone out, but because stories like this are genuinely useful for anyone coming up in SOC/blue team work β recon and finding issues is one skill, but handling disclosure responsibly is the one that actually builds trust and a career.
If you're a defender reading this: check your admin panels today. It takes five minutes and might save you from being my next case study.
Connect With Me
If you found this useful or want to follow more of my Cybersecurity learning journey:
- LinkedIn: Shubham Chaurasiya
- GitHub: @professorshubhx