Back to Glossary

What is Broken Access Control?

Definition

When users can act outside of their intended permissions, commonly ranked as the #1 OWASP risk.

Security Impact

Unauthorized information disclosure, modification of other users' data, and escalation to administrative privileges.

How to Remediate

Enforce RBAC (Role-Based Access Control) or ABAC in middleware. Default to deny. Audit all protected routes.

Want to automatically detect and block Broken Access Control vulnerabilities in your CI/CD pipeline?

Start scanning with Bryxe
Put the definition into practice: security field guides →