Effective 2026-09-25

Reporting a security problem

Email security@topos.network. We acknowledge a report within three business days.

We do not offer a bounty. We do ask, in return for the following, that a researcher report privately and give us time to fix before saying anything in public:

A finding in Apache Fineract itself, rather than in how we deploy it, is owed to the ASF's own private security list first, not to us.

Advisories

Vulnerabilities this build has shipped and fixed, each a row: the platform release that carried the fix, the CVSS score as it was scored (with its version), a plain description, and the reporter where they asked to be named. Each release's own release record, kept by Topos, is the pointer for anyone wanting the detail behind a row.

ReleaseCVSS 3.1DescriptionReporter2026.09.57.4 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)One-time verification codes sent for sign-up and PIN reset were generated with a non-cryptographic random number generator, making them more predictable than a security-sensitive code should be.Internal pen test2026.09.56.8 (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N)The network console kept a signed-in operator's access token in the browser's session storage, readable by any script able to run on that page, rather than a store a script cannot reach.Internal pen test2026.09.55.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)Error responses sent to the app could include the platform's raw internal error text - including up to 600 characters of the core banking engine's own error output - rather than a fixed, safe message.Internal pen test2026.09.54.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N)An internal tool that could simulate network failures between backend services - including one fault that let a payment appear to fail on one side while completing on the other - was guarded by a single shared admin credential rather than an individual login, and using it left no security log entry.Internal pen test2026.09.52.9 (AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)An app's PIN salt was generated with a non-cryptographic random source, and its PIN and one-time code entry fields left the device keyboard's suggestion cache switched on.Internal pen test2026.09.48.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)Internal tools that could list every customer's phone number and act on a customer's behalf - creating accounts, approving credit requests, verifying identity - checked only a shared network access grant, with no individual staff login and no limit on repeated sign-in attempts.Internal pen test2026.09.48.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)A demo convenience endpoint exposed seeded test accounts' PINs and staff operators' passwords in plain text to the shared, cross-market operations console - credentials from one market's system readable from a tool meant to span every market.Internal pen test2026.09.48.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)One-time verification codes sent to customers were written into the same cross-market activity log as ordinary operational events, so anyone able to view that log could read a live code and use it before the customer did.Internal pen test2026.09.46.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)The platform's cross-market activity log carried customers' names, phone numbers, and internal system identifiers that should have stayed inside their originating market's own system.Internal pen test2026.09.46.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)The platform's cross-market activity log recorded free-text details - internal reasons, notes, and error messages - and staff operators' usernames, some of which needed to stay inside their originating market or country rather than reach a shared, cross-market system.Internal pen test2026.09.46.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)The operations console could read customer-identifying data - credit requests, pledge status, payment routing - from any connected market's system using only the console's own login, without the extra check its most sensitive reads warranted, and such reads were not individually logged.Internal pen test2026.09.28.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)The core banking engine ran an unsupported, end-of-life version carrying three unpatched SQL-injection weaknesses, reachable by any signed-in staff operator with basic read access; no vendor-published successor image existed for the platform's deployment architecture until one was built and adopted in its place.Internal pen test2026.09.24.3 (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)The operations console's web server forwarded any path to the underlying core banking engine rather than only its intended REST API, so the engine's own API documentation, health and diagnostics endpoints - which answered without a login - were reachable through it.Internal pen test2026.09.24.1 (AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N)A mobile app release build could silently fall back to the developer's debug signing key, instead of failing, when the intended release key or its password was missing, with nothing in the build pipeline to catch it or record which key had actually signed a build.Internal pen test

Support period

We support a market's deployment for at least five years from that market's production go-live, the end date stated here to at least the month once it is known, and in that market's own pack. No market is live yet, so this reads: at least five years from a market's go-live; no market is live.

Within the support period:

The two apps identify themselves, for support purposes, by their Play Store versionName and versionCode; there is no separate version scheme to track.

Not built: an in-app notice telling a user their app has reached end of support. Where technically feasible, this is an obligation from December 2027 (Cyber Resilience Act, Regulation (EU) 2024/2847, Annex II) and is not yet built.