Skip to content

2026

#144 · Multi-user authentication fallback

With Escape, you can now configure multiple authentication users and enable fallback mode.

Why this matters

At scale, teams may maintain several test users with identical permissions. All of them are valid on paper, but at scan time:

  • One user may already have an active session
  • Some users may be temporarily disabled or locked
  • A user’s password may have been rotated

In those cases, authenticated DAST scans can fail simply because the selected user wasn’t valid when the scan ran, even though another equivalent user would have worked.

When scans are automated and run unattended, this leads to failed scans, retries, and manual intervention, wasting precious time of already quite stretched security teams.

Escape now takes care of selecting the working user for you.

With fallback enabled, Escape will attempt authentication using each configured user and proceed with the first one that succeeds. The scan then runs normally using that user.

This removes the need to decide in advance which specific user a scan should rely on.

How to set it up

  • Go to a dedicated scan profile

    Create or open the scan profile where you want to enable authenticated scanning.

  • Open Settings → Authentication

    This is where authentication behavior is configured for the scan.

  • Enable multi-user fallback

    Turn on fallback mode by setting: multi_user_is_fallback: true

  • Configure multiple users using a Browser Agent preset

In your Browser Agent authentication preset, define all users that can be used interchangeably for the scan.

Here is a full setup example:

presets:
  - type: browser_agent
    users:
      - password: user1
        username: user1@test.com
      - password: user2
        username: user2@test.com
      - password: user3
        username: user3@test.com
      - password: user4
        username: user4@test.com
    login_url: https://example.com/login
    auto_extraction_urls: []
    logged_in_detector_text: Login successful
multi_user_is_fallback: true

If only user3@test.com is active and valid, Escape will attempt authentication with user1@test.com (fails), then user2@test.com (fails), and finally user3@test.com (succeeds). The scan will then proceed using user3@test.com credentials.

Important limitation

Multi-user fallback cannot be used with tenant isolation testing.

Fallback mode runs the scan using a single authenticated user. If you need to test access boundaries between users, run separate scans per user and disable fallback.


This feature is designed to improve reliability of your DAST scans.

Use it when:

  • You have multiple users with the same role
  • Authentication failures occasionally block scans
  • Scans run automatically (CI/CD, scheduled scans)
  • You want scans to complete without manual retries

For more information on enabling fallback mode for multiple users, please refer to our documentation.

#143 · New: MCP Endpoint Discovery & External Scanning in Escape ASM

Escape ASM now natively supports the discovery and external scanning of unauthenticated MCP (Model Context Protocol) endpoints, extending coverage to a new generation of AI-native APIs.

Why this matters

As teams adopt MCP to connect LLMs with tools, data sources, and internal services, new externally exposed attack surfaces are emerging.

Security teams need to:

  • Know where MCP endpoints are exposed
  • Detect unauthenticated or misconfigured MCP servers
  • Reduce blind spots in AI-native infrastructure

This update brings MCP endpoints into Escape ASM’s continuous discovery and monitoring pipeline.

What’s included today

For this initial release, we focused on the ASM layer, fully integrated into existing scans.

Escape ASM now provides:

  • Automatic MCP discovery: MCP endpoints are detected automatically, just like any other internet-facing asset.

  • External surface scanning: Escape analyzes exposed MCP servers and configurations, including:

    • Detection of unauthenticated MCP endpoints
    • Identification of externally reachable MCP services that may present security risks

This helps teams quickly identify high-risk MCP exposures before attackers do.

MCP-discovery-smaller.png

Setup

No setup required. MCP discovery and scanning are enabled by default as part of Escape ASM.

If you’re already running ASM, MCP endpoints are automatically included.

Looking for design partners for next steps in security testing

This release marks the first step toward full ASM + Automated Security Testing coverage for MCP-based architectures. We’re actively looking for design partners using MCP in real-world environments to help shape the next phase of Escape’s security testing for MCPs.

Design partners will get:

  • Early access to authenticated MCP testing
  • Influence over attack scenarios and coverage
  • Direct collaboration with the Escape product team

Reach out to your dedicated Escape contact if you’d like to participate! 🙏