Overview
The number-one risk in the OWASP Top 10: authorization is missing, incomplete or enforced only in the UI.\nClassic patterns are insecure direct object references (changing an id in the URL), missing function-level checks on API routes, and metadata tampering such as JWT claim edits.\nAny user who can read another tenant's invoice has a broken access control finding.
Indicators of Compromise
Signals that suggest this is present on a system.
- Sequential IDs returning other users' data
- Admin routes reachable without an admin session
- 403 only enforced client-side
Controls that stop it
-
Apply Least Privilege Everywhere
Give accounts, processes, tokens and service principals the minimum permissions needed, for the minimum time. Review admin rights and service accounts on a schedule, remove standing privilege, and prefer short-lived credentials over long-lived keys. Deny by default so a missing check fails closed rather than open.