Privilege Escalation Attack Chain: Executive-to-Admin KYC Pipeline Compromise
The affected asset is redacted at the researcher's request.
Summary
A low-privileged Executive user can bypass the authorization restrictions enforced by the dashboard UI and directly access internal Flow management APIs.
The vulnerable API allows the Executive role to enumerate organization Flows and retrieve a Flow's configuration, including a live Flow API key and configuration ID that should only be accessible to privileged roles.
Using these credentials, an Executive can subsequently create and control a new identity-verification session through the underlying KYC APIs, including document submission, liveness/face processing, session scoring, and retrieval of verification results.
This creates an attack chain from Broken Access Control → sensitive credential disclosure → unauthorized KYC session creation and manipulation.