vulns.co
/
GKData.io MCP

AZVulnerability family

Authorization and tenant boundaries.

Object, role, account, and tenant access-control design. 34 disclosures · 83 related references · 10 diagrams.

Connected collection

Disclosures

Google AZAuthorization and tenant boundaries

Google Mamba temporary outputs lacked access isolation

Mamba received a distinct USD 37,604.40 award. The case illustrates why temporary processing output needs explicit access isolation, with retrieval dependencies kept separate from standalone impact.

USD 37,604.40reported awardRead

HackerOne AZAuthorization and tenant boundaries

HackerOne exports omitted internal-attachment authorization

HackerOne awarded $12,500 for internal attachments exposed through report export in 2016. Its enduring lesson for 2026 applications is that export and interactive views must enforce the same visibility policy.

USD 12,500reported awardRead

Meta (Facebook) AZAuthorization and tenant boundaries

Facebook phone linking lacked account-specific authorization

A 2013 researcher disclosure reports a $20,000 award for unauthorized recovery-phone binding. Its enduring lesson for 2026 applications is that recovery-factor possession and account-change authority require separate…

USD 20,000reported awardRead

Connected collection

Related learning

Amazon Web Services Implementation Guide

AWS IAM security best practices for workload identities

Use this guide to review machine identity design: favor short-lived role credentials for workloads, limit permissions to required actions and resources, and retire unnecessary access. It also explains policy validation,…

Reviewed 2026-10-02Read

GitHub Security Lab Research Paper

GraphQL-Ruby: authorization exceptions must stop execution

A GraphQL-Ruby execution-engine path converted a resolver authorization exception into permission to continue. Research demonstrates a denied resolver running and returning a fixture value, while the legacy engine…

Reviewed 2026-10-03Read

Model Context Protocol Technical Standard

MCP elicitation: consent, credential custody and completion

Form elicitation excludes secrets. URL elicitation places sensitive interactions outside the MCP client and model context, with the requesting server and destination visible to the user. Agreeing to open the interaction…

Reviewed 2026-10-04Read

National Institute of Standards and Technology Architecture Guide

NIST SP 800-162: attribute authority and policy traceability

Defines authorization in terms of subject, object, operation and environmental attributes evaluated against policy. Enterprise considerations connect business rules to machine-enforced decisions, attribute authorities…

Reviewed 2026-10-03Read

OpenID Foundation Technical Standard

FAPI 2.0 Security Profile

Defines a high-security OAuth profile with coordinated requirements for confidential clients, authorization servers, and resource servers. Connects sender-constrained tokens and authorization-request integrity with the…

Reviewed 2026-10-03Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Forgot Password

Explains account-bound recovery challenges, limited lifetime and reuse, consistent responses, attempt controls, notifications and post-reset session handling.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

Authorization Cheat Sheet

Practical design guidance covering least privilege, deny-by-default behavior, consistent per-request decisions, failure handling, logging, and authorization regression tests.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

HTML5 Security Cheat Sheet: Web Messaging

OWASP explains origin checks, expected message formats and treating exchanged content as data. These controls address different assumptions at browser communication boundaries.

Reviewed 2026-10-02Read

OWASP Gen AI Security Project Implementation Guide

OWASP LLM05:2025: generated-output consumer trust

Explains why model-generated content remains untrusted when passed to browsers, databases or backend functions. The relevant boundary is the consuming component: plausible model text must not acquire executable meaning…

Reviewed 2026-10-03Read

OWASP Cheat Sheet Series Architecture Guide

LLM Prompt Injection Prevention Cheat Sheet

Defense-in-depth guidance for LLM applications that consume untrusted content or invoke tools. Covers data provenance, least privilege, action authorization, monitoring, and the limitations of guardrails.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Session Management: privilege-transition integrity

Distinguishes application-issued session identifiers from client-selected values. Explains renewing identifiers at login and other privilege changes, retiring previous identifiers, and separating anonymous tracking from…

Reviewed 2026-10-03Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Transaction Authorization

Explains operation-specific approval: show significant transaction details, preserve authorized data, enforce valid state transitions and recheck authorization at execution.

Reviewed 2026-10-02Read

jhb-software / Payload plugins Maintainer Advisory

Payload: request adapters must retain caller-level authorization

CVE-2026-59965 describes authenticated plugin endpoints invoking a privileged server interface without preserving collection-level authorization. Payload's Local API skips access checks by default, so a session check…

Reviewed 2026-10-04Read

Prowler Maintainer Advisory

Prowler SAML: retain validated tenant authority

CVE-2026-59151 concerns token issuance selecting a tenant from an asserted email domain instead of retaining the validated SAML configuration. Maintainers describe potential cross-tenant account takeover. Their…

Reviewed 2026-10-03Read

Internet Engineering Task Force / RFC Editor Technical Standard

RFC 10017: OAuth 2.0 for Browser-Based Applications

Compares browser-only OAuth clients, token-mediating backends, and backend-for-frontend architectures through their different token-custody and session boundaries. Separates protection of token material from the…

Reviewed 2026-10-03Read

Internet Engineering Task Force / RFC Editor Technical Standard

RFC 9700: Best Current Practice for OAuth 2.0 Security

Consensus guidance updating OAuth's security model with deployment experience, stronger protocol requirements, and deprecated insecure patterns. A primary reference for identity integration reviews.

Reviewed 2026-10-02Read

samlify Maintainer Advisory

samlify: signing does not establish claim provenance

The maintainer describes inconsistent escaping between XML attribute and element-text contexts during SAML assertion generation. User-controlled profile values could change assertion structure before the identity…

Reviewed 2026-10-03Read

SLSA Community Security Standard

SLSA v1.2: supply-chain security and build provenance

Learn to assess software supply-chain assurance using distinct source and build tracks. The build track progresses from recording provenance to authenticated hosted builds and stronger platform isolation. Build…

Reviewed 2026-10-02Read

GitHub Security Lab Research Paper

Spree: guest ownership still requires an authorization proof

CVE-2026-25757 concerns completed guest orders. The access decision treated absence of an account owner as sufficient permission, while lookup did not require the separate order token. GHSL identifies the flaw in tested…

Reviewed 2026-10-03Read

World Wide Web Consortium Technical Standard

Fetch Metadata Request Headers

Defines browser-provided request context covering site relationship, destination, mode, and user activation. Explains how redirect history affects that context and why context-dependent responses need matching cache…

Reviewed 2026-10-03Read

WHATWG Technical Standard

HTML COOP: opener separation and same-origin authority

Defines how opener policies affect browsing-context separation during navigation. The standard expressly distinguishes severing an opener relationship from a robust boundary between same-origin documents: storage,…

Reviewed 2026-10-03Read

Connected collection

Visual models

An incoming browser message first passes origin, sender-context and format validation. A separate decision checks the operation and recipient. Failed checks reject the message without disclosure or state change. Approved content remains data and only the permitted action is performed.

Conceptual model Diagram

Browser messages need separate trust checks

Original defensive model combining OWASP messaging and authorization guidance with the linked historical cases. These are independent design checks, not a vendor patch diagram or an operational reproduction.

Reviewed 2026-10-02Read
A caller requests a combined view using required source A and required source B. Each source has its own authorization decision for that caller. Either No denies the combined view without protected source data. Both Yes decisions are required at an explicit AND gate before composition. Field selection preserves each source’s field permissions, and only permitted data is returned.

Conceptual model Diagram

Combined views preserve every source's access boundary

Original conceptual model for a view that requires multiple independently protected sources. Permission to use one source cannot authorize another source. The convergence is an AND requirement: both source decisions…

Reviewed 2026-10-04Read
A failure retains the original caller, action and resource. An explicit access denial stops without protected data. A known recoverable operational failure can propose a fallback, but switching execution identity grants no extra caller entitlement. A separate application-policy decision evaluates that fallback for the original caller. Denied or indeterminate decisions stop without protected data. A permitted, scoped fallback returns only caller-permitted data.

Conceptual model Diagram

Fallbacks must preserve the original caller's authority

Original editorial defensive synthesis of the Instagram embedding disclosure and OWASP authorization guidance. The researcher attributes the disclosure to error handling that retrieved protected content under an…

Reviewed 2026-10-04Read
A request enters a server-side caller, resource and operation authorization decision. Denial returns no protected data. Approval proceeds to explicit field selection before serialization. Only permitted, necessary fields cross into client-visible data. A separate consumer-context handling step keeps content, including generated text, from acquiring executable meaning before display. Browser rendering never supplies server authorization.

Conceptual model Diagram

Server disclosure and browser interpretation

Editorial conceptual model: assumes an application with server-side privileged data and a browser consumer. Next.js guidance supports server authorization and minimal client-visible contracts; OWASP LLM05 supports…

Reviewed 2026-10-03Read
A verified workload identity and a requested operation enter an independent authorization decision. Policy checks the role, action, resource and tenant together. Only the approved resource scope is allowed; other requests are denied. Both decisions produce an audit record.

Conceptual model Diagram

Keep workload authority tenant-scoped

Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.

Reviewed 2026-10-02Read

Related learning follows the topic crosswalk or an explicit diagram relationship. It does not classify a resource as a finding. Topics overlap, so their counts should not be added together.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software