What does Panop test for, and what counts as proof?
Validation is only meaningful if the proof is specific. Each class is confirmed by a technique chosen to demonstrate access without acting on data, and each confirmed finding carries the artefact a remediation engineer needs to reproduce it. Many of these never receive a CVE, which is why CVSS and EPSS scores cannot rank them.
| Vulnerability class | How Panop confirms it | Evidence recorded |
|---|---|---|
| Cloud and edge misconfiguration | Tests permissive storage, over-broad identity policy and CDN or WAF bypass from an untrusted network position. | The bypass route and the resource it reached. |
| Broken authentication and access control | Attempts the privileged action as an unauthenticated or lower-privileged principal to confirm the boundary does not hold. | The boundary crossed and the exact request that crossed it. |
| Exposed interfaces and live credentials | Authenticates against administrative endpoints using discovered or leaked credentials, then stops at confirmation of access. | The endpoint, the credential source and the access confirmation. |
| Remote code execution (RCE) | Command injection, unsafe deserialisation and vulnerable-component paths, proven by an out-of-band callback rather than by running a payload on the host. | The callback record, the entry point and the affected component. |
| Cross-site scripting (XSS) | Establishes that a reflected, stored or DOM-based payload executes in the rendered document, rather than merely appearing in the response body. | The payload, the injection point and the rendered execution context. |
| Injection flaws in application logic | Injects a benign condition into the parameter and compares responses to establish that the query or command is genuinely influenced, without extracting records or acting on data. | The request, the differential response and the affected parameter. |






