Privilege escalation to Admin via invitation role tampering
- Affected asset
- POST /v1/invitations/accept
- Description
- The invitation acceptance request included the invited role as a client-supplied field. The server trusted this value instead of the role stored with the invitation.
- Technical impact
- A user invited as Viewer could accept the invitation with role=admin and obtain Admin privileges in the tenant.
- Business impact
- Unauthorized administrative access to tenant settings, billing details and member management.
POST /v1/invitations/accept HTTP/2{"token":"inv_3f9…","role":"admin"}HTTP/2 200 OK {"membership":{"role":"admin"}}Reproduction steps
- 1.As tenant Owner, invite a new user with role Viewer.
- 2.Intercept the acceptance request from the invited user and change role to admin.
- 3.Observe the resulting membership has the Admin role.
Remediation
- Ignore client-supplied role on acceptance; derive the role from the stored invitation record.
- Reject requests containing unexpected fields for this endpoint.
Retest result
Remediated
Role is now read from the invitation record only; tampered requests are rejected with 400.