Research
How We Overrode OAuth Credentials on a Multi-Tenant Identity Provider
OAuth 2.0 is the backbone of modern authentication. When an identity provider gets it wrong, the blast radius can be enormous. In this write-up, we detail a vulnerability we discovered in a major multi-tenant identity governance platform during a bug bounty engagement, where a flaw in the