Perfai
    Perfai Security · Case Study · Fintech

    135 critical and high-severity authorization findings in a fintech platform

    Perfai Security tested the access controls of a European fintech platform that handles high-value financial assets and sensitive financial records. Our autonomous agents found 135 Critical and High findings, concentrated in function-level authorization.

    European fintechHigh-value financial assetsAccess control testing
    0
    Critical / High findings
    0+
    API endpoints discovered
    ~0K
    Security tests executed
    $0K
    Estimated bug-bounty payouts avoided
    Estimate
    The platform

    A platform where the data and the workflows are the assets

    The platform is a fintech product that organizations use to manage and monitor high-value financial assets. Customers entrust it with sensitive financial records and with workflows that shape financial decisions, so its access controls have to hold for every role and every function, not just the screens users normally see.

    Why it matters

    When money is involved, authorization is the control that counts

    In a financial platform, a user's role defines what they can view and what they can change. Authorization flaws don't crash anything or throw obvious errors: a function reserved for one role quietly answers a request from another. They only surface when every role is tested against every function.

    Role boundary
    A standard role reaches administrative functions while skipping the elevated roleAdministrative functionsElevated roleStandard roleHigh
    What the interface shows vs. what the API accepts
    Interface
    API

    Hiding a button is not the same as enforcing a rule.

    How Perfai tested

    Learn the app, then test every role against every function

    01

    Map the app

    Agents learn the platform the way an attacker would, discovering its workflows, functions, and data.

    02

    Assume every role

    Testing runs as users at each privilege level.

    03

    Test every combination

    Each role is tried against each function, with multiple request variants.

    04

    Prove and report

    Findings are confirmed by the agents before they are reported.

    5 · user roles tested
    90+ · UI workflows mapped
    380+ · API endpoints discovered
    ~80K · tests executed
    Illustrative. Each cell is a role-and-function pair; highlighted cells are authorization violations.
    enforcedviolation
    What we found

    Function-level authorization gaps across the API

    The findings concentrated in Broken Function Level Authorization (OWASP API5:2023): functions that answered requests from roles that should not be able to call them.

    380+ API endpoints
    ~80K security tests
    135 Critical / High findings
    Systematic testing turns a large surface into a short, proven list.

    Administrative and configuration functions

    Setup and configuration functions answered requests from roles that should not manage them.

    Workflow and policy controls

    Functions that govern how internal processes are controlled were reachable beyond their intended roles.

    Financial and reporting data views

    Summary and reporting functions returned data to roles outside their intended audience.

    Access-management information

    Functions that reveal who has access to what could be called by roles that should not see them.

    Each dot is one Critical or High finding.
    Business impact

    Not abstract risk for a financial platform

    $0K
    Estimated bug-bounty payouts avoided
    Estimate, not a measured outcome.

    A single authorization gap in a financial platform can expose sensitive records or let a user act beyond their role. Findings like these would be paid out under a bug-bounty program if reported externally. Finding them first, through structured testing, avoids that cost and the exposure behind it.

    The takeaway for financial platforms

    When a product protects high-value assets and records, authorization across every role and function is the control that matters most. It is also the easiest to miss without testing every combination.

    Find what your last pentest missed.

    Autonomous agents that learn your app, prove the exploit, and ship the fix. No source code required.

    Book a Perfai test →