SECURITY GLOSSARY

BOLA (Broken Object Level Authorization)

BOLA is an API flaw where the server does not check that the caller may access the specific object they asked for, so changing an ID in a request returns someone else’s data. It is first in the OWASP API Security Top 10 (2023).

What it is

BOLA is an API flaw where the server does not check that the caller may access the specific object they asked for, so changing an ID in a request returns someone else’s data. It is first in the OWASP API Security Top 10 (2023).

Why it matters

BOLA leads directly to data exposure across users or tenants, and scanners rarely find it because they cannot tell whose data a response belongs to.

How we test it

We test with at least two users (and two tenants where relevant), swap object identifiers across every endpoint that takes one, and confirm whether authorisation is enforced on the server.

Common mistakes

  • Relying on unguessable IDs instead of authorisation checks
  • Checking access in the UI but not in the API
  • Testing with only one account

An example

GET /api/invoices/1043 returns user A’s invoice; user B sends the same request with their own token and still gets it.

Not to be confused with

BFLA (Broken Function Level Authorization), where the caller can use a function or role they should not have, such as an admin endpoint.

Related at PoCForge

Sources

Need this tested on your systems?

Share your scope and we will propose a human-led plan with proof and a retest.

Request a free scope review →