01Introduction
Broken access control has been number one on the OWASP Top 10 since 2021, and object-level authorization leads the OWASP API Top 10. These bugs are common, severe and almost invisible to traditional tools, because the request is perfectly valid. It just belongs to someone else.
02What is Broken access control?
Broken access control is any failure to enforce what a user is allowed to do. Insecure direct object reference (IDOR), called broken object level authorization (BOLA) in APIs, is the most common form: the app trusts an ID supplied by the user without checking that the user owns the object.
Related business logic vulnerabilities abuse intended features in unintended orders, such as applying a discount twice or skipping a payment step. They are central to API security and a key reason penetration testing finds what SAST and DAST do not.
03How Broken access control works
Finding these flaws means testing as more than one user.
- 1.
Model roles
Identify users, roles, tenants and the objects each should be able to reach.
- 2.
Collect IDs
Capture object identifiers, including UUIDs, from one account's traffic.
- 3.
Swap context
Replay those requests as a different user, role or tenant and compare the responses.
- 4.
Abuse flows
Reorder, repeat or skip steps in multi-step workflows to test business rules.
04Threats and risks
Access control failures lead straight to data breaches.
Cross-tenant access
One customer reads or edits another customer's data in a multi-tenant app.
Privilege escalation
A regular user reaches admin functions by calling the endpoint directly.
Workflow bypass
Steps such as approval or payment are skipped by calling the final step first.
False comfort from UUIDs
Unguessable IDs leak through logs, URLs and other endpoints, then work anywhere.
05How Parameter helps
This is the class of bug Parameter was built to find.
Multi-account agents
AI Pentesting agents test as several users and tenants at once, catching IDOR and cross-tenant access with a working proof.
Caught in review
Sentinel flags missing ownership checks in the pull request that removes or forgets them.
Proven impact
Findings show the exact request that returned another user's data, so severity is never a debate.

