Back to Glossary

What is Insecure Direct Object Reference (IDOR)?

Definition

An access control vulnerability where an application provides direct access to objects based on user-supplied input without authorization checks.

Security Impact

Attackers can read or modify data belonging to other users simply by changing an ID in the URL or API payload.

How to Remediate

Implement strict Row-Level Security (RLS) or explicitly verify that the authenticated user owns the requested resource ID.

Want to automatically detect and block Insecure Direct Object Reference (IDOR) vulnerabilities in your CI/CD pipeline?

Start scanning with Bryxe
Put the definition into practice: security field guides →