How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Two Critical Vulnerabilities, One AI Pentester: How Cascade Found an Unauthenticated RCE and Walked Around the WAF

calendar_today June 30, 2026 person domain escape

Escape points its Cascade AI pentesting solution at a Spring + JSP customer portal, where it uncovers two critical findings, including an unauthenticated remote code execution vulnerability, that are typically hard for traditional DAST tools to catch.

open_in_new Read original post