Forensics Website Penetration Testing Product information New

Broken access control: when users reach what they shouldn't

Transcom 12 Apr 2025, 17:48

Access-control weaknesses are about what a user is allowed to do once they are on your site — and they are among the most common serious flaws found in real-world testing.

Broken access control shows up as things like:

These flaws are dangerous because the site often looks secure — the forbidden options simply aren't shown — while the underlying checks are missing. Automated scanners struggle to spot them because understanding who should be able to do what requires human judgement. A manual tester deliberately tries to step outside their permitted role, and the report details anywhere they succeeded.

0 comments

Sign in with your TDesk account to comment.

← Back to all posts