arXiv · 2507.17007
The Postman: A Journey of Ethical Hacking in PosteID/SPID Borderland
Abstract
This paper presents a vulnerability assessment activity that we carried out on PosteID, the implementation of the Italian Public Digital Identity System (SPID) by Poste Italiane. The activity led to the discovery of a critical privilege escalation vulnerability, which was eventually patched. The overall analysis and disclosure process represents a valuable case study for the community of ethical hackers. In this work, we present both the technical steps and the details of the disclosure process.
Explore related subjects
Keep this discovery
Gabriele Costa. 2025-07-22. The Postman: A Journey of Ethical Hacking in PosteID/SPID Borderland. https://arxiv.org/abs/2507.17007
Cite the original work for its findings. Save a collection to share your selection of sources.