See it work
This page shows how a finding is meant to be read. The record below is from Nubesti Security Lab. It is not a customer, not a production hostname, and not a third-party disclosure.
Lab record
| Field | Value |
|---|---|
| Asset | api.lab.nubesti.test |
| Finding | Broken object-level authorization |
| Severity | Critical |
| MITRE ATT&CK | T1190 — Exploit Public-Facing Application |
| Evidence | Request / response pair from a controlled lab replay |
| Exploitability | Validated in the lab (object ID swapped; another tenant record returned) |
| Impact | Unauthorized read of another account’s records in the lab dataset |
| Suggested remediation | Enforce object-level authorization on every record access; add a regression test |
| Status | Fixed in lab build 2026.09 |
| Retest | Passed |
Product walkthrough
The embed below is a product tour. Treat it as a walkthrough of the interface, not as evidence about a named customer.
To run tests on your own assets: complete paid KYC, confirm authorization, then use the portal.
Ready to test an
authorized scope?
Paid KYC before tests
Evidence on each finding
Portal stop control