Pentest Files: How A Single HTTP Header Unlocked Every Customer’s Data

Screenshot 2026 03 18 At 14.00.59

A single HTTP header. Fully client-controlled. Trusted completely by the server. In this Pentest Files, Daniel shows how modifying one value in a routine API request was enough to pull user data from every organisation on a multi-tenant SaaS platform, no special privileges required, no complex exploit chain, just a for loop and an integer.