API2:2023: Broken Authentication
Authentication mechanisms that are flawed, missing, or implemented incorrectly. Includes weak credential handling, missing rate limits on auth endpoints, JWT validation flaws.
How it's found
Found by probing API authentication endpoints for weak JWT validation, missing multi-factor enforcement, and tolerance of credential stuffing.
Standards mapping
How TurboPentest tests for this
TurboPentest tests authentication dynamically, following the OWASP testing guides across login, session, and multi-factor flows to find bypasses and weak credential handling. Paladin AI chains findings across requests to surface multi-step authentication weaknesses. A manual IntegSec engagement applies deeper methodology.
Tools: Paladin AI, Web Scanner
Frequently asked questions
What is API2:2023 Broken Authentication?
Authentication mechanisms that are flawed, missing, or implemented incorrectly. Includes weak credential handling, missing rate limits on auth endpoints, JWT validation flaws.
How do you find Broken Authentication?
Found by probing API authentication endpoints for weak JWT validation, missing multi-factor enforcement, and tolerance of credential stuffing.
Which CWEs map to API2:2023?
API2:2023 maps to CWE-287, CWE-306, CWE-798.
Does TurboPentest test for Broken Authentication?
TurboPentest tests authentication dynamically, following the OWASP testing guides across login, session, and multi-factor flows to find bypasses and weak credential handling. Paladin AI chains findings across requests to surface multi-step authentication weaknesses. A manual IntegSec engagement applies deeper methodology.
Related OWASP categories
- OWASP API Security Top 10API1:2023: Broken Object Level Authorization
- OWASP API Security Top 10API3:2023: Broken Object Property Level Authorization
- OWASP API Security Top 10API4:2023: Unrestricted Resource Consumption
- OWASP API Security Top 10API5:2023: Broken Function Level Authorization
- OWASP API Security Top 10API6:2023: Unrestricted Access to Sensitive Business Flows
- OWASP API Security Top 10API7:2023: Server Side Request Forgery (SSRF)
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest