Skip to content
REDMAW

SaaS & Identity

Over-Broad SaaS Sharing Links

Files, records or workspaces can be reachable outside the intended identity boundary when link-sharing or external access is broader than expected.

RedMaw

Definition

Collaboration platforms allow content to be shared by link, with an external party, or across an entire organization. Exposure arises when the effective audience of that share is wider than the person sharing understood.

Why this is not a misconfiguration in the usual sense

Nothing failed. Every share was created deliberately by someone with permission to create it. The problem is cumulative: individually reasonable decisions, made over years, by people who could not see the aggregate result.

The useful question

Reporting that link-sharing is enabled is not a finding. It is a product feature. The finding is what becomes reachable because of it: which sensitive records, to which audience, and whether that audience still includes people who have left.

Where it leads
  1. Sharing Configuration
  2. External Link
  3. SaaS Resource
  4. Sensitive Records

Each hop validated by successful exploitation

Tags

  • saas posture
  • data exposure
  • sharing

Validation

How RedMaw validates this attack

Validation runs only inside authorized scope, with agreed exploitation limits.

  1. 01Enumerate sharing configuration across the authorized tenant
  2. 02Identify content reachable without the expected identity boundary
  3. 03Establish the sensitivity of what is actually reachable
  4. 04Distinguish intended external collaboration from unintended exposure

Stop assuming you are secure. Prove it.

Continuously test what an attacker can actually reach across your applications, SaaS identities, internal infrastructure and AI systems.