Summary by Aman12321
Identified a broken access control vulnerability (P1/Critical) on a NASA/JPL production web application. The application's API allowed unauthenticated users to create, read, and delete any user's saved data using only a name as the identifier - with no session, cookie, or token required. Additionally, an unauthenticated email relay endpoint was discovered. The issue was triaged, confirmed, and resolved by NASA's security team.