Perfai
    Perfai Security · Case Study · KSA Multi-Tenant Platform

    104 critical and high access-control flaws in a KSA multi-tenant security platform

    Perfai Security tested the access controls of a multi-tenant enterprise security platform deployed in KSA. Our autonomous agents found 104 Critical and High authorization flaws, including cross-tenant access.

    KSA deploymentMulti-tenantAccess control testing
    Tenant isolation
    A user crosses a tenant isolation boundary to reach records in another tenantTenant ATenant BIsolation boundaryCritical
    0
    Critical / High access-control findings
    0
    Critical cross-tenant access findings
    0
    Function-level authorization flaws (BFLA)
    $0K
    Estimated bug-bounty payouts avoided
    The platform

    A platform organizations trust with sensitive security data

    The platform is a multi-tenant enterprise security product. Organizations use it to centralize, analyze, and act on security information, with separate tenants, user roles, and administrative functions. Because customers rely on it to keep their data isolated and its controls enforced, authorization is the most consequential thing it has to get right.

    Why it matters

    In a multi-tenant product, authorization is the trust boundary

    Two questions decide whether a multi-tenant platform can be trusted. Can a user in one tenant reach another tenant's data? Can a lower-privilege user call functions reserved for higher-privilege roles? Neither shows up as a crash or an error. They only surface when roles, functions, and objects are tested systematically.

    Role boundary
    A standard user reaches administrator functions without the elevated roleAdministrator functionsElevated roleStandard userHigh
    How Perfai tested

    Every tenant, every role, every function

    01

    Map the app

    Agents learn the app the way an attacker would, discovering its functions, workflows, and object types.

    02

    Assume every role

    Testing runs as users in different tenants and at different privilege levels.

    03

    Test every combination

    Each role is tried against each function and object, including cross-tenant requests.

    04

    Prove and report

    Findings are confirmed by the agents before they are reported.

    Illustrative grid of enforced and failed role-and-function pairs
    enforcedHighCritical
    Illustrative. Each cell is a role-and-function pair; highlighted cells are authorization violations.
    What we found

    Systemic gaps in function-level and object-level authorization

    Every finding below is an access-control failure: something a user could do or reach that their tenant and role should not allow.

    104 Critical and High findings divided among three access-control categories104Critical / High
    Object-level access weaknesses68
    Function-level authorization34
    Cross-tenant access2
    Critical 2High 102

    Cross-tenant access

    Critical · 2
    Tenant isolation

    A user in one tenant could read data belonging to another tenant, breaking the isolation that multi-tenant customers depend on.

    Function-level authorization (BFLA)

    High · 34
    OWASP API5:2023

    Standard tenant users could call functions reserved for higher-privilege roles, including administrative and configuration functions (such as identity and integration settings) and some that create or modify records.

    Object-level access weaknesses

    High · 68
    OWASP API1:2023

    Predictable object identifiers across many resource types made records enumerable by an authenticated user, an object-level authorization weakness.

    Business impact

    The cost of finding them late

    Each of these is the kind of issue that would be paid out under a bug-bounty program if reported externally. Finding them through structured testing avoids that cost, and the exposure behind it.

    $0K
    Estimated bug-bounty payouts avoided

    Estimate, not a measured outcome.

    Each dot is one finding.

    Takeaway: tenant isolation has to be tested, not assumed

    For a multi-tenant security product, isolation between tenants and separation between roles are promises made to every customer. Testing every role against every function and object is how those promises get verified.

    Find what your last pentest missed.

    Autonomous agents that learn your app, prove the exploit, and ship the fix. No source code required.

    Book a Perfai test →