← Reference
Access control

A regular user can perform admin actions

Broken Function Level Authorization

What this means

Administrative actions — deleting data, exporting user lists, changing settings — work for anyone who knows the address. The button is hidden in the interface, but the request still succeeds.

Why it matters

A hidden button only protects against accidental clicks. Admin addresses are easy to spot in page source, and the damage is irreversible: deleted data and exported lists do not come back.

When this is not a problem

Actions deliberately open to all users are not a finding.

How to fix it

  • Check the user's role on the server for every administrative action.
  • Treat access as denied by default and open it explicitly.

Prompt for your AI agent

Protect administrative actions with a server-side role check: anything admin-only must return 403 for a regular user.

Verify the fix: call an admin action from a regular account — expect a refusal

ClassificationCWE-285CWE-863· API5:2023 · A01:2021
Is your app doing this?
Find out in about a minute — the first scan is free.
Scan your app
A regular user can perform admin actions — seleth