Unbranded commercial passenger aircraft flying above the clouds at dawn.

Find vulnerabilities.
Assess legal risk.

I assess airline websites and APIs to identify vulnerabilities and their legal implications. As a lawyer and security researcher with over 60 responsibly disclosed vulnerabilities, I also design private Labs for airline security teams.

Application security research informed by legal expertise.

01 / Passenger data02 / Booking platforms03 / Airline teams

Services

Application security
for airlines.

Security assessments, legal risk analysis and private Labs for the teams responsible for passenger platforms. Every engagement begins with a defined scope and written authorisation.

01 / ASSESS

Web & API security assessments

Testing of access controls, business logic and sensitive data exposure in booking systems, passenger accounts and APIs, with findings prioritised by impact.

Discuss an assessment
02 / PRACTISE

Private Labs for airline teams

Practical vulnerability investigations for your security team, using simulated airline applications in an isolated environment.

Explore the Labs
03 / UNDERSTAND

Data protection & legal risk

Analysis of how security findings affect personal data and the organisation’s obligations, taking account of the relevant jurisdiction and agreed scope.

Discuss legal risk

Private Labs

Investigate vulnerabilities.
Develop remediation plans.

Private sessions dedicated to your airline’s security team. Using simulated applications and synthetic passenger data, participants investigate vulnerabilities, assess their impact and propose fixes in an isolated environment.

  • Scenarios based on booking flows, passenger accounts and loyalty programmes
  • Simulated systems with synthetic passenger data
  • Guided review of findings, remediation choices and defensive controls
Discuss a private Lab
PRIVATE LAB / BOOKINGS

Who can access this reservation?

The team investigates a simulated booking flow to identify authorisation flaws, assess exposed data and propose controls that address the cause.

BOOKINGACCESS CONTROLDATA EXPOSURE
Isolated environmentFictional data

Approach

Evidence to guide remediation.

Each assessment follows an agreed scope, tests actual application workflows and produces reproducible evidence with prioritised recommendations. The method is adapted to your systems and operational requirements.

01

Define the scope

Agree on the systems, access, written authorisation and rules of engagement before testing begins.

02

Test application workflows

Examine identity, booking and data access controls as they operate across passenger workflows.

03

Assess and prioritise risk

Document reproducible findings, their technical and legal implications, and recommendations ranked by impact.

04

Support remediation

Review remediation options with your team and verify fixes when retesting is included in the agreed scope.

Airline application security expert

Lawyer & application security researcher

Luciano
Paccella.
Working across Europe and worldwide

Security of airline applications and the personal data they handle.

About me

Security research with legal expertise.

I am Luciano Paccella, a lawyer and application security expert specialising in airlines. My work examines access control failures, business logic flaws and personal data exposure in airline systems and other large digital platforms.

A Law graduate of Universidad Nacional de Rosario, I have conducted application security research since December 2022, with over 60 vulnerabilities responsibly disclosed to international aviation and technology companies. This work combines technical evidence with analysis of the consequences for passengers and organisations’ data protection responsibilities.

My experience includes black-box and grey-box assessments, contributions through airline responsible vulnerability disclosure programmes and presentations on booking system security at Ekoparty.

When a vulnerability exposes personal data, assessing its severity also requires an understanding of the legal consequences. My security research experience and legal expertise allow me to examine both the technical failure and the responsibilities it may entail for the organisation.

View my professional profile

Achievements

A track record in airline security research.

60+

Vulnerabilities responsibly disclosed

Access control failures, business logic flaws and other vulnerabilities reported to international aviation and technology companies through responsible disclosure.

Professional background
2024

Ekoparty Maintrack speaker

Presented research with Ignacio Laurence on airline booking vulnerabilities, passenger data exposure and the associated legal implications.

Conference presentation
2026

Ekoparty Miami speaker

Delivered a talk on authorisation, scope and the legal and operational responsibilities involved in vulnerability research.

Talk and participation
Early

Early remediation to reduce legal exposure

My findings have helped companies promptly identify and correct vulnerabilities that could expose personal data, helping to reduce the risk of exposure and potential legal claims. Technical evidence and legal analysis give organisations a sound basis for acting in time.

Airline contributions

Research contributions to airline security.

I contribute findings through airline responsible vulnerability disclosure programmes. The following references document my work and the public recognition it has received.

Responsible vulnerability disclosure programme

United Airlines

Research contributions through the airline’s responsible vulnerability disclosure programme, with recognition in its Hall of Fame.

Hall of Fame · June 2024

Responsible vulnerability disclosure programme

International Airlines Group

Recognition for contributions to the group’s public responsible vulnerability disclosure programme, recorded in my professional profile.

Hall of Fame · July 2024

Additional airline contributions

  • Aer Lingus
  • Air France
  • Breeze Airways
  • British Airways
  • Finnair
  • Iberia
  • Qantas
  • Saudia
  • Vueling

These contributions reflect my experience in identifying vulnerabilities and protecting data in the airline sector.

Selected public research

Published research on booking security.

Two published investigations into weaknesses that can expose passenger information. Each summary covers the findings presented at the time of publication and does not assess an airline’s current security.

01 / RESERVATIONS

Unauthorised access to passenger bookings

Research findings
Research presented with Ignacio Laurence at Ekoparty 2024 examined weaknesses in booking verification and insufficient protection against repeated reservation lookups.
Potential impact
Unauthorised parties could access passenger information and itineraries. Some affected workflows could also permit changes to a booking.
Recommended controls
Enforce authorisation for each reservation and protect sensitive actions with appropriate access controls.
See the public presentation

02 / GRAPHQL APIs

Booking enumeration through API responses

Research findings
My published analysis examines how multiple booking checks in a single GraphQL request can reveal whether a booking reference and passenger surname form a valid combination.
Potential impact
Response differences can confirm valid booking details. Limits that count only HTTP requests may fail to account for the number of booking checks within each request.
Recommended controls
Apply limits to individual booking checks and restrict response details that reveal whether reservation data is valid.
Read the published analysis

Contact

Discuss security
for your airline.

Contact me to discuss a security assessment, the legal implications of a finding or a private Lab for your team. Describe your priorities by email or LinkedIn.

Please avoid sending credentials, passenger data or vulnerability details in an initial message.

Email

Describe your organisation’s priorities and the assessment, legal analysis or Lab you need.

lpaccella@airflysecurity.com

Contact by email

LinkedIn

Message me through my professional profile to discuss your security priorities and project scope.

linkedin.com/in/lucianopaccella

Contact on LinkedIn