A01 - Broken Access Control 38
- Local File Inclusion via Template Router | CostThis
- IDOR in Password Reset API Leads to Administrator Account Takeover | TheForms
- Password Change IDOR Leads to Administrator Account Takeover | Noted
- Multi-Step Access Control Bypass Leads to Administrative Compromise | Tamper Temple
- Local File Inclusion via Language Cookie Leads to Arbitrary File Read | Flagged
- GraphQL Role Parameter Abuse Leads to Restricted Medical Note Disclosure | Clearance
- Authentication Bypass – Direct Dashboard Access | Pivot HR
- IDOR – Unauthorized Grant Approval via Workflow Manipulation | Briarcliff Foundation
- Privilege Escalation – Unsigned Session Token Tampering | Spindrift Workspace
- Privilege Escalation – Client-Side Role Cookie Tampering | Session Swap
- Privilege Escalation – JWT None Algorithm Abuse | Stargate Atlas
- Mass Assignment – Role Escalation | Salt Brook Pilates
- IDOR – Account Export Data Disclosure | Remittance
- SSRF – Internal Service Discovery Through Monitor Preview Feature | Statuscraft
- X-Forwarded-For Spoofing – Internal Staff Portal Access Control Bypass | Brackish Brewing Co.
- SSRF Blocklist Bypass – Internal File Disclosure via Localhost Filtering Evasion | CutCorner
- Missing Access Control – Unrestricted Staff Portal Exposure | Coltsfoot Community Center
- Information Disclosure – Sensitive Debug Header Leakage via Response Metadata | Header Hunt
- Workflow Access Control Bypass – Admin Privilege Escalation | Lazy Human Resources
- IDOR via WebSocket Subscription – Cross-Order Data Exposure | JoyStick
- GraphQL BOLA via Introspection & Insecure Resolver Access | Slate Quarry
- Mass Assignment Leading to Admin Account Creation | Trellis
- IDOR via Sequential Order IDs | Cheesy Does It
- IDOR in Order Access – Unauthorized Order Data Exposure | Hartwood
- GraphQL Introspection and Sensitive Data Exposure | Ottergram
- UUID-Based IDOR Through Member API | Apex
- XML External Entity (XXE) via Deck Import Feature | Tanuki
- Path Traversal – Arbitrary File Read via Image Endpoint | Ottergram
- IDOR – Unauthorized Access to Borrower Records | Overdue
- Broken Access Control – Admin Access Token Brute Force Leads to Unauthorized Admin Access | Gift List
- Broken Access Control – Role Manipulation via User Registration | Tanuki
- IDOR – Unauthorized Access to Shared Notes via Base64 ID Manipulation | BugForge
- Broken Access Control – Unauthorized Stats Modification via HTTP Method Manipulation | BugForge
- IDOR – Password Disclosure via Insecure Direct Object Reference | User ID Controlled by Request Parameter
- IDOR – Unauthorized Access via Predictable Identifier Manipulation | User ID Controlled by Request Parameter
- Broken Access Control – Privilege Escalation via Client-Controlled Cookie | Privilege Escalation via Client-Controlled Cookie
- Broken Access Control – Unprotected Admin Panel via Unpredictable URL Leading to Privilege Escalation | Unprotected Admin Panel
- Broken Access Control – Unprotected Admin Functionality Leading to Privilege Escalation | Unprotected Admin Functionality