What did the scanner miss?
Reconcile automated findings with cross-user probes. A CVE count is not authorization coverage; the boundary is the evidence.
Use synthetic IDs only. Blank observed_status means the boundary was not executed.
Scanner findings and authorization proof are different evidence.
Run the audit to separate known-CVE records, manual boundary outcomes, exposed fields, and missing execution evidence.
Authorization evidence map
Known findings imported; authorization coverage is not inferred.
No exposed fields classified.
Interpretation
A cross-user request that should deny access but returns a 2xx response is classified as a bypass. A scanner finding remains separate evidence; its presence cannot close an untested authorization boundary.
Evidence boundary
This local tool does not scan a live app or prove exploitability, CVE validity, identity, session behavior, business impact, or remediation. Confirm every result in an authorized test environment.