Web & API security assessments
Testing of access controls, business logic and sensitive data exposure in booking systems, passenger accounts and APIs, with findings prioritised by impact.
Discuss an assessment
I assess airline websites and APIs to identify vulnerabilities and their legal implications. As a lawyer and security researcher with over 60 responsibly disclosed vulnerabilities, I also design private Labs for airline security teams.
Application security research informed by legal expertise.
Services
Security assessments, legal risk analysis and private Labs for the teams responsible for passenger platforms. Every engagement begins with a defined scope and written authorisation.
Testing of access controls, business logic and sensitive data exposure in booking systems, passenger accounts and APIs, with findings prioritised by impact.
Discuss an assessmentPractical vulnerability investigations for your security team, using simulated airline applications in an isolated environment.
Explore the LabsAnalysis of how security findings affect personal data and the organisation’s obligations, taking account of the relevant jurisdiction and agreed scope.
Discuss legal riskPrivate Labs
Private sessions dedicated to your airline’s security team. Using simulated applications and synthetic passenger data, participants investigate vulnerabilities, assess their impact and propose fixes in an isolated environment.
The team investigates a simulated booking flow to identify authorisation flaws, assess exposed data and propose controls that address the cause.
Approach
Each assessment follows an agreed scope, tests actual application workflows and produces reproducible evidence with prioritised recommendations. The method is adapted to your systems and operational requirements.
Agree on the systems, access, written authorisation and rules of engagement before testing begins.
Examine identity, booking and data access controls as they operate across passenger workflows.
Document reproducible findings, their technical and legal implications, and recommendations ranked by impact.
Review remediation options with your team and verify fixes when retesting is included in the agreed scope.
Lawyer & application security researcher
LucianoSecurity of airline applications and the personal data they handle.
About me
I am Luciano Paccella, a lawyer and application security expert specialising in airlines. My work examines access control failures, business logic flaws and personal data exposure in airline systems and other large digital platforms.
A Law graduate of Universidad Nacional de Rosario, I have conducted application security research since December 2022, with over 60 vulnerabilities responsibly disclosed to international aviation and technology companies. This work combines technical evidence with analysis of the consequences for passengers and organisations’ data protection responsibilities.
My experience includes black-box and grey-box assessments, contributions through airline responsible vulnerability disclosure programmes and presentations on booking system security at Ekoparty.
When a vulnerability exposes personal data, assessing its severity also requires an understanding of the legal consequences. My security research experience and legal expertise allow me to examine both the technical failure and the responsibilities it may entail for the organisation.
View my professional profileAchievements
Access control failures, business logic flaws and other vulnerabilities reported to international aviation and technology companies through responsible disclosure.
Professional backgroundPresented research with Ignacio Laurence on airline booking vulnerabilities, passenger data exposure and the associated legal implications.
Conference presentationDelivered a talk on authorisation, scope and the legal and operational responsibilities involved in vulnerability research.
Talk and participationMy findings have helped companies promptly identify and correct vulnerabilities that could expose personal data, helping to reduce the risk of exposure and potential legal claims. Technical evidence and legal analysis give organisations a sound basis for acting in time.
Airline contributions
I contribute findings through airline responsible vulnerability disclosure programmes. The following references document my work and the public recognition it has received.
Responsible vulnerability disclosure programme
Research contributions through the airline’s responsible vulnerability disclosure programme, with recognition in its Hall of Fame.
Hall of Fame · June 2024
Responsible vulnerability disclosure programme
Recognition for contributions to the group’s public responsible vulnerability disclosure programme, recorded in my professional profile.
Hall of Fame · July 2024
Additional airline contributions
These contributions reflect my experience in identifying vulnerabilities and protecting data in the airline sector.
Selected public research
Two published investigations into weaknesses that can expose passenger information. Each summary covers the findings presented at the time of publication and does not assess an airline’s current security.
01 / RESERVATIONS
02 / GRAPHQL APIs
Contact
Contact me to discuss a security assessment, the legal implications of a finding or a private Lab for your team. Describe your priorities by email or LinkedIn.
Please avoid sending credentials, passenger data or vulnerability details in an initial message.