The deliverable

The report is the product.

01

Cover

Engagement metadata first. Anyone picking the document up six months later can read what was tested, when, by whom and against which version.

CB-2026-014  ·  v1.0
Penetration Test Report — Acme Corp
Web Application
Assessment.
Client
Acme Corp
Issued
2026-03-22
Prepared by
Covert Binary
02

Executive summary

Plain language, for the people signing the cheque. What was tested, what was found, what it means for the business, what to do first. No CVSS, no jargon. Findings appear as a one-glance heatmap with impact stated in money or in regulatory terms, not in technical severity alone.

A longer board write-up is available on request, complimentary with any engagement.

02 · EXECUTIVE SUMMARY

What we found

Across the 3-week engagement, we identified 14 findings, of which 2 are critical and require immediate action. The most material issue is an authentication bypass in the customer-facing API that exposes data for any tenant given a single valid token.

Patched in parallel during testing: 6 findings. Outstanding at report delivery: 8.

SEVERITY SPLIT · 14 FINDINGS
CRIT 2 HIGH 3 MED 5 LOW 3 INFO 1
REMEDIATION AT DELIVERY
PATCHED IN TESTING 6 OUTSTANDING 8
PRIORITISED ACTION
CRIT CB-001 · Tenant authentication bypass in customer API 7 DAYS
CRIT CB-002 · SSRF in import service reaches IMDSv1 7 DAYS
HIGH CB-003 · Stored XSS on shared workspace settings page 30 DAYS
WHERE THE FINDINGS SIT
Customer API · api.acme.com4
Web application · app.acme.com5
Import service · internal3
Build and release pipeline2
CB-2026-014 · ACME CORP PAGE 2 OF 38
03

Technical findings

One structured page per finding: title, CVSS v3.1 vector and score, business impact, affected components, evidence, numbered reproduction steps, and remediation. Fix-in-context code where it helps.

The same findings come as CSV or JSON on request, with ID, title, severity, owner and status pre-filled, so they drop into Jira, Linear or GitHub Issues.

Want to read the real thing? A full sanitised report goes out under NDA. Ask by email and it comes back quickly.

Request a sanitised report →
CB-001 CRITICAL CVSS 9.8 · AV:N/AC:L/PR:N/UI:N

Tenant authentication bypass via predictable workspace token

Component
api.acme.com /v2/workspaces/:id
Endpoint
GET /v2/workspaces/:id/secrets
Auth
Workspace bearer token (any tenant)
DESCRIPTION

The workspace bearer token is derived from a non-cryptographic hash of the workspace identifier. An authenticated user in any workspace can derive valid tokens for arbitrary other workspaces and read their secrets.

REPRODUCTION
$ curl -H "Authorization: Bearer $(cb-token 49213)" \ https://api.acme.com/v2/workspaces/49213/secrets
{"ok": true, "secrets": [...]}
EVIDENCE
HTTP/2 200
content-type: application/json

{"ok": true, "workspace": 49213, "owner": "northwind-ltd",
  "secrets": [{"key": "stripe_live", "value": "sk_live_••••"}]}
REMEDIATION

Replace the derived token with an opaque, server-issued workspace token bound to the authenticated user. Invalidate all existing tokens on rotation. See appendix A for a drop-in middleware patch.

Discovered2026-03-04
Confirmed byManual exploitation
StatusOutstanding
Fix window7 days
CB-2026-014 · ACME CORP PAGE 11 OF 38