Broken Object Level Authorization
Also known as:BOLA
Broken Object Level Authorization: Missing check of whether the caller is allowed to access the specific object requested. BOLA is the API form of the insecure direct object referenceInsecure Direct Object ReferenceAccess control flaw where object identifiers enable unauthorized access. and tops the OWASP API Top 10.
How it works and where it fits
The application authenticates the caller correctly but never verifies that the requested object ID belongs to them. A valid token is then enough to iterate through other people’s records. Crucially, the gap exists per endpoint and per method: a properly protected read path says nothing about PUT, PATCH, or DELETE. Side effects count too — a write operation that echoes the raw object in its response can disclose data the read path masks.
Practical security relevance
Only a central, object-level check immediately before each access is effective, derived from the session identity rather than from request parameters. Hard-to-guess identifiers raise the cost but do not replace the check. Because BOLA resists signature-based detection, automated tests with two separate accounts belong in the pipeline: whatever account A can see, account B must be denied.
Related concepts
- Insecure Direct Object ReferenceInsecure Direct Object ReferenceAccess control flaw where object identifiers enable unauthorized access.: Access control flaw where object identifiers enable unauthorized access.
- AuthorizationAuthorizationDecision regarding which actions an authenticated identity is permitted to perform.: Decision regarding which actions an authenticated identity is permitted to perform.
- API SecurityAPI SecurityProtects APIs against misuse, unauthorized access, and data-related attacks.: Protects APIs against misuse, unauthorized access, and data-related attacks.
- Access ControlAccess ControlGoverns who is permitted to access specific systems, data, or functions.: Governs who is permitted to access specific systems, data, or functions.