Sanaan Fayaz Wani

Sanaan Fayaz Wani

Security Engineer at Amazon, bringing agentic AI into identity and access management. Independent vulnerability research across open source infrastructure.

  • 7CVEs assigned
  • 12Advisories published
  • 7Projects credited
  • 167Reports filed
  • 59Projects audited

01

Profile

Amazon, Cyber Florida, University of South Florida. Independent vulnerability research separately.

Sanaan Fayaz Wani is a Security Engineer at Amazon, working in IAM security on bringing agentic AI into identity and access management. Outside that, he hunts unauthenticated remote code execution in the infrastructure that runs large language models: agent frameworks, inference servers, workflow orchestrators, and the serialization formats they trust.

Before Amazon he was a security researcher at Cyber Florida, building agentic systems for open source vulnerability research and working on industrial control system security. The summer before that he was on Amazon’s red team, building an autonomous system for red teaming and tooling against Model Context Protocol servers while the protocol was still new. He graduated magna cum laude in computer science from the University of South Florida in May 2026, where he competed with the CyberHerd team.

Disclosure

The work listed here is coordinated disclosure. Every finding is reported privately to the maintainer first, and nothing is named, listed or hinted at until a fix ships. What that leaves is a record anyone can check: each entry resolves to an advisory the maintainer published and credited.

02

Advisories

Every entry is published, fixed and credited. Nothing is named here until the maintainer ships a fix. The full record, with each CVSS base vector set out metric by metric, is on the advisories page.

NRAdvisoryProjectCVSSSeverityWeaknessPublished
01CVE-2026-57516ray8.8HighCode injection2026-07-24
02CVE-2026-45675open-webui8.1HighPrivilege escalation2026-05-14
03GHSA-pqxw-g93w-hj9xtrigger.dev8.1HighImproper isolation2026-10-02
04GHSA-jc26-22qp-cgqjtrigger.dev7.9HighMissing authentication2026-09-14
05GHSA-3c52-v5v2-3r56budibase7.7HighServer side request forgery2026-09-17
06CVE-2026-59714open-webui7.1HighMissing authorization2026-07-24
07GHSA-8p4j-2mm9-rh78Tracecat6.5MediumServer side request forgery2026-09-20
08CVE-2026-53577io.kestra:kestra6.5MediumIncorrect authorization2026-06-03
09CVE-2026-63342github.com/hatchet-dev/hatchet6.3MediumIncorrect authorization2026-09-22
10GHSA-59h8-w5q6-mfmptrigger.dev5.3MediumMissing authentication2026-10-02
11CVE-2026-73301@budibase/server4.3MediumMissing authorization2026-07-24
12CVE-2026-59715open-webui3.1LowMissing authentication2026-07-24

03

Weakness classes

Four recurring, in rough order of volume.

  1. Unauthenticated reachability

    An auth gated code execution sink is a bug. The same sink reachable before auth is a critical. Most of the highest severity findings here are reachability failures rather than novel sinks: missing authentication and missing authorization in front of machinery that was never meant to be public.

  2. Sandboxes that are not sandboxes

    Agent frameworks ship “safe” Python evaluators built on AST allowlists. Format string dunder traversal, decorator abuse, and incomplete node denylists walk straight out of most of them.

  3. Deserialization on exposed ports

    pickle, cloudpickle, joblib, and torch.load(weights_only=False) sitting behind an inference or actor pool port that quietly binds 0.0.0.0.

  4. Request forgery into control planes

    The highest volume class: metadata endpoints, internal schedulers, and cluster APIs one redirect away from a user supplied URL.

Current interests

Agentic systems and autonomous loops, and what happens to authorization when an agent acts on a user’s behalf across many services: how delegated identity and least privilege survive an agent that plans its own steps, and where the tool invocation boundary quietly becomes an execution boundary. It is the same question as the day job, from the other direction.

04

Method

Reproduced before reported. Private first, public only after the fix.

Nothing is reported from code reading alone. Every finding is reproduced against a running instance first, with a real request and real output, because runtime behaviour routinely makes theoretically vulnerable code unexploitable.

Reports go to maintainers privately, through GitHub Security Advisories or the project’s stated security channel, never a public issue tracker, and nothing is named or mirrored publicly until the maintainer publishes.

Target layer

The layer underneath the model: agent frameworks, inference servers, workflow orchestrators, vector stores, and the serialization formats they trust. These projects grow quickly, bind to broad interfaces by default, and add execution features faster than they add authorization.

Focus areas

AI agent security · LLM infrastructure security · agentic systems · autonomous agents · identity and access management · vulnerability research · coordinated disclosure · sandbox escape · unsafe deserialization · server side request forgery

05

Record

Roles, degree, certifications and competition results as of September 2026. Dates are YYYY.MM.

  1. 2026.06–
    present

    Amazon / Security Engineer

    Identity and access management. Bringing agentic AI into IAM, which is the same question as the independent research from the other direction: what happens to authorization when an agent acts on a user’s behalf across many services.

  2. 2026.05
    graduated

    University of South Florida / BSc Computer Science, cybersecurity focus

    Graduated magna cum laude. CyberHerd, USF’s cybersecurity competition team; former Blue Team Captain.

  3. 2025.08–
    2026.05

    Cyber Florida / Security Researcher

    Florida Center for Cybersecurity, the state’s cybersecurity center, hosted at the University of South Florida. Worked in the Cyber Florida SOC. Built agentic systems for open source vulnerability research, automating discovery and triage work that normally has to be done by hand. Also worked on industrial control systems security.

  4. 2025.05–
    2025.08

    Amazon / Security Engineer Intern, Red Team

    Built an autonomous agentic system for red team operations, and worked with the Model Context Protocol early in its life, before the tooling and the practice around it had settled.

Certifications

  1. 2026

    GICSP / Global Industrial Cyber Security Professional

    GIAC, via SANS ICS410: ICS/SCADA Security Essentials.

  2. 2025

    CBBH / Certified Bug Bounty Hunter

    Hack The Box.

Competitions

  1. 20261stAI Village CTF, DEF CON 34Won an NVIDIA DGX Spark
  2. 20262ndAdversary Wars CTF, Adversary Village, DEF CON 34Won a certification
  3. 20261stCorelight CTF, GuidePoint SecurityWon a PlayStation 5
  4. 20261stHackabull CTFWon computer accessories
  5. 20262ndHack The MadnessWon swag
  6. 20251stAdversary Wars CTF, Adversary Village, DEF CON 33Won a certification
  7. 20251stHackabull CTFWon swag and a lockpick set
  8. 20251stSocial Engineering Competition, The CARE Lab at Temple UniversityWon a cash prize
  9. 20252ndSHPE National CTFWon a cash prize
  10. 20252ndCPTC Southeast RegionalsWon a heartbreak
  11. 20253rdSecureTheFuture Research Award, Palo Alto NetworksWon a cash prize
  12. 20253rdNCAE CyberGames, South East RegionalsWon swag
  13. 20241stSHPE National CTFWon a cash prize
  14. 20241stCentral Florida Tech Grove CTFWon a cash prize

06

Coverage

Third party sources that name him, newest first.

  1. Cyber Florida Career Launch Series: From SOCAP to Security Engineering Work shout out
  2. Cyber Florida Technical Threat Advisory: CVE-2026-45675 Credits the CVE discovery
  3. University of South Florida 138th Commencement Convocation, Spring 2026 Degree and honors, page 56
  4. USF Bellini College USF’s CyberHerd team dominates in CyberHawk CTF win College shout out
  5. USF Bellini College USF CyberHerd captures first place at world’s largest hacker conference College shout out
  6. USF College of Engineering USF CyberHerd Team Dominates National Cybersecurity Competitions in 2024 College shout out
  7. SHPE 2024 SHPE National Convention Highlights Official winners roster, page 9
  8. USF College of Engineering CyberHerd Member Leads Team to Victory and a $4,500 Prize at SHPE National Convention College shout out

07

Contact