Broken Access Control
A class of vulnerabilities in which an application fails to enforce what users are allowed to do, letting them view or change data or perform functions outside their intended permissions.
Access control enforces policy so that users cannot act outside their intended permissions. It breaks when checks are missing, performed only in the user interface or based on values the client can manipulate. Common forms include insecure direct object references, where changing an identifier in a URL or API call exposes another user's record; vertical privilege escalation to administrative functions; missing checks on API methods; tampering with tokens or cookies that carry roles; and CORS misconfiguration that allows untrusted origins.
Broken access control ranked first in the OWASP Top 10 2021, with more occurrences in the contributed test data than any other category. It is especially relevant to multi-tenant software, customer portals and APIs, where a single missing authorisation check can expose data belonging to every customer. Automated scanners find some cases, but many require testers who understand the business logic and the intended roles.
Effective controls are enforced on the server for every request, deny access by default except for public resources, and are implemented once in a shared mechanism rather than repeated ad hoc. Record-level ownership checks, rate limiting of API access, logging of access-control failures and invalidation of sessions at logout all help. Role-based or attribute-based access control models should follow the principle of least privilege and be covered by automated tests.
Key points
- Ranked first in the OWASP Top 10 2021.
- Includes insecure direct object references, privilege escalation and missing function-level checks.
- Checks must be enforced server-side on every request, denying by default.
- Business-logic flaws often need manual testing to find.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- OWASP Top 10Cybersecurity & Compliance
- Principle of Least PrivilegeCybersecurity & Compliance
- API SecurityCybersecurity & Compliance
- Penetration TestingCybersecurity & Compliance
- Cross-Origin Resource Sharing (CORS)Cybersecurity & Compliance
- Zero Trust Architecture (ZTA)Cybersecurity & Compliance