vulns.co
/
GKData.io MCP

IDVulnerability family

Authentication and identity.

Account lifecycle, session integrity, identity-provider trust. 16 disclosures · 44 related references · 4 diagrams.

Connected collection

Disclosures

Meta (Facebook) AZAuthorization and tenant boundaries

Facebook phone linking lacked account-specific authorization

A 2013 researcher disclosure reports a $20,000 award for unauthorized recovery-phone binding. Its enduring lesson for 2026 applications is that recovery-factor possession and account-change authority require separate…

USD 20,000reported awardRead

Connected collection

Related learning

Amazon Web Services Implementation Guide

AWS IAM security best practices for workload identities

Use this guide to review machine identity design: favor short-lived role credentials for workloads, limit permissions to required actions and resources, and retire unnecessary access. It also explains policy validation,…

Reviewed 2026-10-02Read

Google Chrome for Developers Implementation Guide

Chrome bfcache: restored pages and session-state boundaries

Explains Chrome’s conditional admission of no-store pages to the back/forward cache. A restored page resumes in-memory document state rather than performing a fresh network load. The guide describes eviction safeguards…

Reviewed 2026-10-03Read

Model Context Protocol Technical Standard

MCP elicitation: consent, credential custody and completion

Form elicitation excludes secrets. URL elicitation places sensitive interactions outside the MCP client and model context, with the requesting server and destination visible to the user. Agreeing to open the interaction…

Reviewed 2026-10-04Read

National Institute of Standards and Technology Architecture Guide

NIST SP 800-162: attribute authority and policy traceability

Defines authorization in terms of subject, object, operation and environmental attributes evaluated against policy. Enterprise considerations connect business rules to machine-enforced decisions, attribute authorities…

Reviewed 2026-10-03Read

OpenID Foundation Technical Standard

FAPI 2.0 Security Profile

Defines a high-security OAuth profile with coordinated requirements for confidential clients, authorization servers, and resource servers. Connects sender-constrained tokens and authorization-request integrity with the…

Reviewed 2026-10-03Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Forgot Password

Explains account-bound recovery challenges, limited lifetime and reuse, consistent responses, attempt controls, notifications and post-reset session handling.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

Authorization Cheat Sheet

Practical design guidance covering least privilege, deny-by-default behavior, consistent per-request decisions, failure handling, logging, and authorization regression tests.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

HTML5 Security Cheat Sheet: Web Messaging

OWASP explains origin checks, expected message formats and treating exchanged content as data. These controls address different assumptions at browser communication boundaries.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Session Management: privilege-transition integrity

Distinguishes application-issued session identifiers from client-selected values. Explains renewing identifiers at login and other privilege changes, retiring previous identifiers, and separating anonymous tracking from…

Reviewed 2026-10-03Read

Prowler Maintainer Advisory

Prowler SAML: retain validated tenant authority

CVE-2026-59151 concerns token issuance selecting a tenant from an asserted email domain instead of retaining the validated SAML configuration. Maintainers describe potential cross-tenant account takeover. Their…

Reviewed 2026-10-03Read

Internet Engineering Task Force / RFC Editor Technical Standard

RFC 10017: OAuth 2.0 for Browser-Based Applications

Compares browser-only OAuth clients, token-mediating backends, and backend-for-frontend architectures through their different token-custody and session boundaries. Separates protection of token material from the…

Reviewed 2026-10-03Read

Internet Engineering Task Force / RFC Editor Technical Standard

RFC 9700: Best Current Practice for OAuth 2.0 Security

Consensus guidance updating OAuth's security model with deployment experience, stronger protocol requirements, and deprecated insecure patterns. A primary reference for identity integration reviews.

Reviewed 2026-10-02Read

samlify Maintainer Advisory

samlify: signing does not establish claim provenance

The maintainer describes inconsistent escaping between XML attribute and element-text contexts during SAML assertion generation. User-controlled profile values could change assertion structure before the identity…

Reviewed 2026-10-03Read

Connected collection

Visual models

An incoming browser message first passes origin, sender-context and format validation. A separate decision checks the operation and recipient. Failed checks reject the message without disclosure or state change. Approved content remains data and only the permitted action is performed.

Conceptual model Diagram

Browser messages need separate trust checks

Original defensive model combining OWASP messaging and authorization guidance with the linked historical cases. These are independent design checks, not a vendor patch diagram or an operational reproduction.

Reviewed 2026-10-02Read
A verified workload identity and a requested operation enter an independent authorization decision. Policy checks the role, action, resource and tenant together. Only the approved resource scope is allowed; other requests are denied. Both decisions produce an audit record.

Conceptual model Diagram

Keep workload authority tenant-scoped

Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.

Reviewed 2026-10-02Read

Related learning follows the topic crosswalk or an explicit diagram relationship. It does not classify a resource as a finding. Topics overlap, so their counts should not be added together.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software