← Reference
Access control

Anyone can open someone else's record

Broken Object Level Authorization (BOLA/IDOR)

What this means

Your app returns records by their number without checking who owns them. Change one digit in the address and you see another customer's order, profile or document.

Why it matters

This is the most common way customer databases leak. It takes no skill — a browser and curiosity are enough. The leak looks like normal app traffic, so it usually goes unnoticed for months.

When this is not a problem

Resources that are public by design — product catalogues, blog posts — are not a finding.

How to fix it

  • Check ownership on the server for every request, not just in the interface.
  • Compare the record's owner with the current user before returning any data.
  • Answer with a refusal rather than an empty result — that way tests catch the mistake.

Prompt for your AI agent

Add a server-side ownership check: users must only receive their own records. If a record belongs to someone else, return 403 instead of the data.

Verify the fix: sign in as a second account and request the first account's record — expect a refusal

ClassificationCWE-639CWE-285· API1:2023 · A01:2021
Is your app doing this?
Find out in about a minute — the first scan is free.
Scan your app
Anyone can open someone else's record — seleth