Meridian customer portal
Penetration test report
SNT-8C24A1October 3, 2026Executive summary
Assessment completeResolve the authorization gaps before release.
Magier AI validated 4 security findings on staging.meridian-commerce.example. 2 open issues require priority remediation because of the impact on account permissions and customer data. Testing used 2 approved test identities within the agreed scope.
Technical findings
4 validatedWhat was observed
The invitation endpoint accepted an administrator role from a member account. The invited test user received permissions reserved for account administrators.
| Record / captured at | Evidence type | Recorded observation |
|---|---|---|
PT_8C24A1-F2 | HTTP exchange | 201 Created · Administrator invitation |
A member could grant administrative access within its own account, including access to team settings and billing. Validation was limited to an isolated test account and an approved test invitee.
POST /api/team/invitations HTTP/1.1
Host: staging.meridian-commerce.example
Authorization: Bearer [REDACTED MEMBER SESSION]
Content-Type: application/json
{"email":"alex.chen@meridian-commerce.example","role":"admin"}HTTP/1.1 201 Created
Content-Type: application/json
{"invite_id":"invtn_8c4912","role":"admin","account_id":"acct_mrc_7314"}Scope & coverage
staging.meridian-commerce.exampleTest accountTesting was limited to these hosts. Related assets require a separate scope approval.
Reachable application routes and API entry points
Ownership checks across two approved identities
Session lifecycle and sign-out invalidation
Role assignment in an isolated test account
Testing approach
Identify application entry points and confirm the supplied test context.
Compare the suspected behavior with control requests. Request approval before cross-account checks or test-data changes.
Attach masked request evidence and actionable fixes. Retest each finding in a fresh session using its original scope.
This report describes the behavior validated during this engagement. Untested routes, identities, and control areas are outside its conclusions.