Parameter

What is Broken access control?

Broken access control, BOLA and IDOR

What broken access control, BOLA and IDOR are, why they top the OWASP Top 10, and why scanners miss the business logic flaws that agents find.

01Introduction

Broken access control has been number one on the OWASP Top 10 since 2021, and object-level authorization leads the OWASP API Top 10. These bugs are common, severe and almost invisible to traditional tools, because the request is perfectly valid. It just belongs to someone else.

02What is Broken access control?

Broken access control is any failure to enforce what a user is allowed to do. Insecure direct object reference (IDOR), called broken object level authorization (BOLA) in APIs, is the most common form: the app trusts an ID supplied by the user without checking that the user owns the object.

Related business logic vulnerabilities abuse intended features in unintended orders, such as applying a discount twice or skipping a payment step. They are central to API security and a key reason penetration testing finds what SAST and DAST do not.

03How Broken access control works

Finding these flaws means testing as more than one user.

  1. 1.

    Model roles

    Identify users, roles, tenants and the objects each should be able to reach.

  2. 2.

    Collect IDs

    Capture object identifiers, including UUIDs, from one account's traffic.

  3. 3.

    Swap context

    Replay those requests as a different user, role or tenant and compare the responses.

  4. 4.

    Abuse flows

    Reorder, repeat or skip steps in multi-step workflows to test business rules.

04Threats and risks

Access control failures lead straight to data breaches.

  • Cross-tenant access

    One customer reads or edits another customer's data in a multi-tenant app.

  • Privilege escalation

    A regular user reaches admin functions by calling the endpoint directly.

  • Workflow bypass

    Steps such as approval or payment are skipped by calling the final step first.

  • False comfort from UUIDs

    Unguessable IDs leak through logs, URLs and other endpoints, then work anywhere.

05How Parameter helps

This is the class of bug Parameter was built to find.

  • Multi-account agents

    AI Pentesting agents test as several users and tenants at once, catching IDOR and cross-tenant access with a working proof.

  • Caught in review

    Sentinel flags missing ownership checks in the pull request that removes or forgets them.

  • Proven impact

    Findings show the exact request that returned another user's data, so severity is never a debate.

[ AI Pentesting ]

See how Parameter AI Pentesting fits your Broken access control program.

Autonomous agents that find, prove and fix what matters. Every finding ships with evidence.