Security Engineer at Amazon, bringing agentic AI into identity and access management. Independent vulnerability research across open source infrastructure.
01
Amazon, Cyber Florida, University of South Florida. Independent vulnerability research separately.
Sanaan Fayaz Wani is a Security Engineer at Amazon, working in IAM security on bringing agentic AI into identity and access management. Outside that, he hunts unauthenticated remote code execution in the infrastructure that runs large language models: agent frameworks, inference servers, workflow orchestrators, and the serialization formats they trust.
Before Amazon he was a security researcher at Cyber Florida, building agentic systems for open source vulnerability research and working on industrial control system security. The summer before that he was on Amazon’s red team, building an autonomous system for red teaming and tooling against Model Context Protocol servers while the protocol was still new. He graduated magna cum laude in computer science from the University of South Florida in May 2026, where he competed with the CyberHerd team.
Disclosure
The work listed here is coordinated disclosure. Every finding is reported privately to the maintainer first, and nothing is named, listed or hinted at until a fix ships. What that leaves is a record anyone can check: each entry resolves to an advisory the maintainer published and credited.
02
Every entry is published, fixed and credited. Nothing is named here until the maintainer ships a fix. The full record, with each CVSS base vector set out metric by metric, is on the advisories page.
| NR | Advisory | Project | CVSS | Severity | Weakness | Published |
|---|---|---|---|---|---|---|
| 01 | CVE-2026-57516 | ray | 8.8 | High | Code injection | 2026-07-24 |
| 02 | CVE-2026-45675 | open-webui | 8.1 | High | Privilege escalation | 2026-05-14 |
| 03 | GHSA-pqxw-g93w-hj9x | trigger.dev | 8.1 | High | Improper isolation | 2026-10-02 |
| 04 | GHSA-jc26-22qp-cgqj | trigger.dev | 7.9 | High | Missing authentication | 2026-09-14 |
| 05 | GHSA-3c52-v5v2-3r56 | budibase | 7.7 | High | Server side request forgery | 2026-09-17 |
| 06 | CVE-2026-59714 | open-webui | 7.1 | High | Missing authorization | 2026-07-24 |
| 07 | GHSA-8p4j-2mm9-rh78 | Tracecat | 6.5 | Medium | Server side request forgery | 2026-09-20 |
| 08 | CVE-2026-53577 | io.kestra:kestra | 6.5 | Medium | Incorrect authorization | 2026-06-03 |
| 09 | CVE-2026-63342 | github.com/ | 6.3 | Medium | Incorrect authorization | 2026-09-22 |
| 10 | GHSA-59h8-w5q6-mfmp | trigger.dev | 5.3 | Medium | Missing authentication | 2026-10-02 |
| 11 | CVE-2026-73301 | @budibase/server | 4.3 | Medium | Missing authorization | 2026-07-24 |
| 12 | CVE-2026-59715 | open-webui | 3.1 | Low | Missing authentication | 2026-07-24 |
03
Four recurring, in rough order of volume.
An auth gated code execution sink is a bug. The same sink reachable before auth is a critical. Most of the highest severity findings here are reachability failures rather than novel sinks: missing authentication and missing authorization in front of machinery that was never meant to be public.
Agent frameworks ship “safe” Python evaluators built on AST allowlists. Format string dunder traversal, decorator abuse, and incomplete node denylists walk straight out of most of them.
pickle, cloudpickle, joblib, and torch.load(weights_only=False) sitting behind an inference or actor pool port that quietly binds 0.0.0.0.
The highest volume class: metadata endpoints, internal schedulers, and cluster APIs one redirect away from a user supplied URL.
Current interests
Agentic systems and autonomous loops, and what happens to authorization when an agent acts on a user’s behalf across many services: how delegated identity and least privilege survive an agent that plans its own steps, and where the tool invocation boundary quietly becomes an execution boundary. It is the same question as the day job, from the other direction.
04
Reproduced before reported. Private first, public only after the fix.
Nothing is reported from code reading alone. Every finding is reproduced against a running instance first, with a real request and real output, because runtime behaviour routinely makes theoretically vulnerable code unexploitable.
Reports go to maintainers privately, through GitHub Security Advisories or the project’s stated security channel, never a public issue tracker, and nothing is named or mirrored publicly until the maintainer publishes.
Target layer
The layer underneath the model: agent frameworks, inference servers, workflow orchestrators, vector stores, and the serialization formats they trust. These projects grow quickly, bind to broad interfaces by default, and add execution features faster than they add authorization.
Focus areas
AI agent security · LLM infrastructure security · agentic systems · autonomous agents · identity and access management · vulnerability research · coordinated disclosure · sandbox escape · unsafe deserialization · server side request forgery
05
Roles, degree, certifications and competition results as of September 2026. Dates are YYYY.MM.
2026.06–
present
Identity and access management. Bringing agentic AI into IAM, which is the same question as the independent research from the other direction: what happens to authorization when an agent acts on a user’s behalf across many services.
2026.05
graduated
Graduated magna cum laude. CyberHerd, USF’s cybersecurity competition team; former Blue Team Captain.
2025.08–
2026.05
Florida Center for Cybersecurity, the state’s cybersecurity center, hosted at the University of South Florida. Worked in the Cyber Florida SOC. Built agentic systems for open source vulnerability research, automating discovery and triage work that normally has to be done by hand. Also worked on industrial control systems security.
2025.05–
2025.08
Built an autonomous agentic system for red team operations, and worked with the Model Context Protocol early in its life, before the tooling and the practice around it had settled.
2026
GIAC, via SANS ICS410: ICS/SCADA Security Essentials.
2025
Hack The Box.
06
Third party sources that name him, newest first.
07