Skip to content

Broken Access Control: Finding It Deliberately

The most common serious weakness in modern applications, and the methodical way to test for it.

Editorial team 2 min read

Access control is where most real breaches of web applications begin, because it is the one thing a framework cannot do for you: only the application knows who should see what.

Two accounts, every time

The method is dull and effective. Create two accounts in each role — two customers, two administrators, a customer and a staff member — then take every request one can make and replay it as the other, changing only the identifier. Watch for: full responses, partial responses, different error codes, and timing differences that reveal existence.

Where to look

Object references. Any identifier in a URL, body, header or cookie. Sequential integers make the test obvious; UUIDs make it harder, not safer, since identifiers leak through exports, notifications and search.

Functions. Endpoints that the interface only shows to administrators but the server does not check. Enumerate from the client bundle, the API schema, and old versions of the API that nobody retired.

Fields. Mass assignment: sending role=admin or account_id=other in an update that the server copies wholesale.

Tenancy. In multi-tenant systems, the tenant identifier must be enforced server-side on every query, never taken from the request.

What good looks like

Authorisation decided in one place, close to the data, from the authenticated identity — never from a parameter the client controls. Then the test above returns 403 every time, which is the only result worth having.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025