October 10, 2026
One-Click Account Deletion: How a Direct Link Can Instantly Delete an Authenticated User’s Account
AccountBy Mohamed Elasswy (@0xfalcon) Web Security Researcher | Bug Bounty Hunter

By 0xfalcon
1 min read
about me:
I'm Mohamed Elasswy, (0xfalcon), a Cybersecurity Researcher and Bug Bounty Hunter focused on finding security vulnerabilities in web applications and APIs. I enjoy exploring applications, identifying security flaws, and helping organizations improve their security through responsible disclosure.
Overview
During a bug bounty assessment, I discovered an endpoint that could close an authenticated user's account simply by opening a direct URL.
I reported the issue, but the triage team rejected the submission because one important question remained unanswered: How could an attacker obtain the victim's pivot_uid?
Instead of giving up on the finding, I went back to the application and continued exploring its functionality. I browsed through the site while monitoring requests and responses in Burp Suite.
I then searched through the HTTP history for the identifier. That's when I found it: the required value was exposed in a booking-related response under the name business_uid.
With that missing piece identified, the attack scenario became much clearer.
Steps to Reproduce
- Browse the application while capturing traffic in Burp Suite.
- Search the HTTP history for
business_uid. - Inspect the corresponding response and retrieve the identifier.
- Use the identifier in the following URL:
https://www.test.com/account/close?frontage_iframe=true&pivot_uid=<business_uid>- Open the URL in a browser authenticated to the test account.
- Observe that the account closure action is triggered without an additional confirmation step.
Impact
An attacker who obtains the required identifier could craft a direct link that may trigger account closure when opened by an authenticated user, potentially causing loss of account access and disruption to associated business operations.
the bounty