Authorisation Flaws (BOLA and Beyond)
APIs expose objects and records directly, so the most damaging flaw is authorisation: reading or changing another user's or tenant's data by changing an ID.
We test for broken object-level authorisation (BOLA), broken function-level authorisation and broken authentication across every role, proving where one account can reach another's data across user and tenant boundaries.
- BOLA
- Broken auth
- Tenant isolation
