This document is a penetration test report conducted for ACME Corp on February 4, 2026, by Aikido. The primary objective of the assessment was to evaluate the security posture of ACME Corp's web application and identify vulnerabilities that could be exploited by attackers. The report details the findings of the penetration test, which revealed a total of 2 critical, 4 high, 5 medium, and 2 low vulnerabilities. Key issues identified include hardcoded default admin credentials and an unauthenticated password reset flaw, both of which pose significant risks to the application’s integrity and user data confidentiality. The report outlines specific recommendations for remediation, including the need to address critical weaknesses in authentication and account management, improve business logic controls, and enhance API security measures. The findings emphasize the importance of addressing these vulnerabilities to mitigate potential risks associated with data breaches and unauthorized access. Additionally, the report includes a master findings table categorizing each identified vulnerability by severity and remediation status.