It started as a routine Black-Box engagement.
No credentials, no prior knowledge, just a brief and a challenge — test the security of a well-known data analytics system used by one of our clients.
Our team at ICT Strypes stepped in, ready to dig beneath the surface. What we found, however, was anything but routine.
In early 2025, a client enlisted ICT Strypes’ penetration testing team to assess the security of their data analytics system. The client used Alteryx Server, a platform by Alteryx, a company specializing in Big Data and AI analytics solutions. Approaching the task with a Black-Box methodology, our team had no prior knowledge of the system’s internals.
We began by examining the application’s interfaces, methodically checking for vulnerabilities. During this process, we uncovered an authentication bypass flaw that could allow an unauthorized user to create a session and gain Administrator-level access, affecting Built-In and SAML authentication. Such access could enable an attacker to target the client’s internal infrastructure or impact end-users of the compromised server.
Understanding the issue’s severity, we documented the finding thoroughly and reported it to Alteryx. The company responded promptly, releasing a fix within 10 days for versions 2025, 2024, and 2023, though versions 2022, 2021, and 2020 remained unpatched due to end-of-life status. This finding safeguarded the client’s analytics environment and enhanced Alteryx Server’s security for global users, highlighting the value of independent testing.
You can read the official fix release notes from Alteryx here:
At ICT Strypes, we’re passionate about thorough exploration, so the authentication bypass was just one of several vulnerabilities we uncovered. We conducted additional research on Alteryx products and found even more interesting opportunities, which we managed to chain together into multi-stage attack and impact infrastructure and end-users. Here is a sneaky, partial and redacted preview of the attack
You can now read the complete research, including exploits, attack chain, and other details: Less is mighty!
Get in touch with our experts today.