Full-Scope Penetration Test Uncovers Systemic Multi-Tenant Isolation Failure
Found that multiple backend services derived tenant identity from a client-supplied request header instead of the authenticated session — letting any authenticated user read and write every other tenant's data — and delivered a severity-ranked fix path ahead of the platform's SOC 2 assessment.
Client: Multi-Tenant B2B SaaS Platform Operator — Microservices Architecture
- Industry
- B2B SaaS · Multi-Tenant Platform
- Engagement
- Grey-box penetration test · Backend microservices, API, and web application, SOC 2-driven
Challenge
The client operates a multi-tenant SaaS platform, delivered as a set of backend microservices behind an API gateway, where each tenant's data must stay strictly isolated from every other tenant's. A SOC 2 assessment was approaching, and the client needed independent, technical assurance that tenant isolation actually held under adversarial testing — not just architectural intent.
Approach
A grey-box assessment across the full service estate: authenticated testing from multiple tenant contexts run in parallel to actively probe for cross-tenant leakage, paired with authorization and session-handling review on every exposed service, and targeted black-box reconnaissance of the public-facing surface. The methodology deliberately tested trust boundaries between services, not just each service in isolation.
Key Activities
- ▸ Tested every exposed backend service from multiple distinct tenant identities in parallel to surface cross-tenant data leakage systematically, not incidentally
- ▸ Reviewed how each service derived and enforced tenant identity and session authentication
- ▸ Mapped which services enforced authentication and authorization consistently versus which trusted client-supplied context
- ▸ Probed multi-stage business workflows for sequence-bypass and post-approval tampering
- ▸ Performed black-box reconnaissance of the public-facing surface to validate exposure independent of the authenticated findings
- ▸ Delivered findings ranked by real cross-tenant blast radius, not just individual CVSS score
Results
Business Impact
Technologies & Service Areas
Related Services
Client names and identifying details are withheld. This case study is a sanitized account shared with the client's consent.