BOLA
Broken object-level authorisation
When changing an identifier in a request lets you read somebody else's record.
The check that should happen is whether this user may see this specific object. Where that check is missing, an interface that looks private is public to anyone who can guess an identifier.
It is consistently the most common serious flaw in AI-built web applications, because the code that fetches a record is easy to generate and the code that authorises it is easy to leave out.
It leaks other people's data with no exploit and no tooling. A changed number in an address bar is enough.
Assuming a framework handles it. Row-level security has to be written and it has to be tested with two different accounts.
Related terms
See BOLA on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue