Thursday, 1 October 2026

OWASP API Risks Updated - BOLA

As AI use and sophistication grow, BOLA attacks have risen rapidly.  Broken Object Level Authorisation (BOLA) is when an authenticated user can switch parameters like the URL in an API request and access other users' data. For example, GET https://api.example.com?client=32 returns the authenticated user's information, such as your age or other PII.

The authenticated user changes the client to "33"; I now get someone else's records, as the API only checks that I am an authenticated user, not that I am authorised to check another client.

ActionURLResult
GEThttps://api.example.com?client=32The user sends valid authentication for their own client.  The result returns their data.  Correct.
GEThttps://api.example.com?client=33The user sends valid authentication for their own client data but requests another client's info.  The result returns the other client's private data.  Incorrect behaviour.  Major security issue.

Tools like Wiz and StackHawk will pick up BOLA API weaknesses.

0 comments:

Post a Comment