Skip to content
StrikeCyberStrikeCyber
Technology & SaaS

Web and API Penetration Test for a SaaS Platform

A multi-tenant SaaS platform needed adversary-grade testing of its web app and APIs before a major enterprise rollout.

Technology & SaaS sector
Industry
Technology & SaaS
Services
Penetration Testing
Engagement
Web application and API penetration test
Region
National

The Challenge

The client operates a multi-tenant SaaS platform used by business customers across Australia. The product had grown quickly, with new features, integrations and API endpoints shipped on a tight release cadence. That pace had outrun security review, and the platform was about to onboard several large enterprise accounts that expected independent assurance before signing.

The core concern was tenant isolation. In a multi-tenant model, a single authorisation flaw can let one customer reach another customer's data, which is both a breach and a contractual failure. The security team needed a rigorous, real-world assessment of the web application and the APIs behind it, focused on how an authenticated attacker or a malicious customer would actually behave. They wanted proof, not a scanner report, and a clear path to remediation before the enterprise rollout.

Our Approach

StrikeCyber scoped an authenticated web application and API penetration test covering the customer-facing portal, the underlying REST APIs and the multi-tenant authorisation model. Testing was carried out by expert operators using an AI-augmented offensive security platform to accelerate reconnaissance while people drove the exploitation.

  • External attack surface mapping and endpoint enumeration, including undocumented and legacy API routes not exposed in the interface.
  • Authenticated testing from multiple tenant and role perspectives to probe authentication, session management and authorisation boundaries between accounts.
  • Business logic and workflow testing against the flows that matter commercially, such as billing, invitations, role changes and data export.

Every automated signal was validated and exploited by hand, so authorisation and logic flaws that scanners cannot confirm were proven with evidence. Findings were delivered through a live client portal as they were confirmed, giving developers actionable detail while the engagement was still running. You can read more about our penetration testing methodology.

What We Found

  • Broken access control through insecure direct object references. By manipulating object identifiers in API requests, an authenticated user in one tenant could read and modify records belonging to another tenant, breaking the isolation the platform depends on.
  • Authentication and session weaknesses. Password reset tokens did not expire promptly and session invalidation on logout was incomplete, widening the window for account takeover.
  • Missing API rate limiting. Sensitive endpoints, including login and a data export function, had no effective throttling, enabling credential stuffing and bulk data extraction.
  • Exploitable business logic. A flaw in the team invitation and role assignment flow allowed a standard user to escalate their own privileges to an administrative role within their tenant.

The Outcome

StrikeCyber delivered a prioritised remediation plan written for the engineering team, with proof-of-concept detail for each finding and clear reproduction steps. The broken access control issues were fixed with server-side authorisation checks enforced on every object and tenant boundary. Session handling was corrected, reset tokens were given short lifetimes, and rate limiting was applied across authentication and export endpoints. The privilege escalation path in the invitation flow was closed with proper server-side role validation.

A follow-up retest confirmed the critical and high findings were remediated and verified, that data could no longer be enumerated across tenants, and that the privilege escalation path was gone. The client entered its enterprise rollout with documented, independent assurance of tenant isolation and a hardened API layer, and used the report to satisfy the security review requirements of its new enterprise customers.

Why It Matters

For a SaaS business the API is the product, and the flaws that cause the most damage are authorisation and business logic errors that no automated scan will confirm. In a multi-tenant platform those flaws translate directly into cross-tenant data exposure and lost enterprise deals. Human-led SaaS penetration testing shows exactly how a real attacker or malicious customer would break isolation, turning a sales blocker into demonstrable trust. If you are preparing for an enterprise security review, get in touch to scope an assessment.

Ready to take the offensive?

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation