Pentest Files: How A Single HTTP Header Unlocked Every Customer’s Data

Screenshot 2026 03 18 At 14.00.59

A single HTTP header. Fully client-controlled. Trusted completely by the server. In this Pentest Files, Daniel shows how modifying one value in a routine API request was enough to pull user data from every organisation on a multi-tenant SaaS platform, no special privileges required, no complex exploit chain, just a for loop and an integer.

Pentest Files: Hijacking Admin Invitations to Bypass the Login Wall

Screenshot 2026 02 24 At 14.38.49

OnSecurity’s Pentest Files uncovers the latest vulnerabilities and real-life remediation steps to prevent businesses from malicious attack. In this article we find out how our Head of Pentesting is able to hijack admin invitations to bypass the login wall in our clients infrastructure.