Hunting Tenant Onboarding And Discovery Abuse

Hunt for multi-tenant SaaS onboarding and organization-discovery flows that let an attacker join, claim, or enumerate a tenant they should not: a self-service signup that auto-joins a new user to an existing organization by email domain so anyone with a matching address lands inside it, a domain-claim step that can be satisfied without proving ownership so an attacker claims a domain and its users, an invitation whose token is guessable, reusable, or not bound to the invited address, a tenant-discovery endpoint that reveals which organizations or domains exist, and a first-admin race where claiming an unclaimed org grants admin over users who later join. Use when joining or claiming a tenant, or learning that one exists, is the boundary between an outsider and an organization's data. The onboarding or discovery request is the source, the unauthorized tenant membership, claim, or enumeration is the sink, and the unverified domain claim or unbound invitation is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/hunting-tenant-onboarding-and-discovery-abuse commit 1882ea0ef7

Frequently asked questions

npx skillmds@latest add unboundcompute/hunting-tenant-onboarding-and-discovery-abuse