Skip to content

H3-2026-0061

Improper Authorization

Category VULNERABILITY
Base Score 5.0

Description

The application did not enforce role-based authorization on privileged resources. A request restricted to a higher-privileged role, replayed with a lower-privileged role's credentials substituted in, returned the protected content or completed the action.

Impact

An attacker holding a low-privilege account can reach functionality or data reserved for a higher-privileged role, escalating their effective privileges within the application.

References