API5:2023: Broken Function Level Authorization
Attackers can call admin/elevated functions with regular-user credentials by manipulating endpoints or HTTP methods.
How it's found
Identified by re-issuing admin and privileged API calls under low-privilege credentials to test for vertical privilege escalation.
Standards mapping
How TurboPentest tests for this
TurboPentest tests authorization and access control dynamically, exercising object-level and function-level checks across privilege boundaries per the OWASP testing guides. Paladin AI chains vulnerabilities to find privilege-escalation paths. Multi-role business-logic depth is where a manual engagement adds a larger context window.
Tools: Paladin AI, Web Scanner
Frequently asked questions
What is API5:2023 Broken Function Level Authorization?
Attackers can call admin/elevated functions with regular-user credentials by manipulating endpoints or HTTP methods.
How do you find Broken Function Level Authorization?
Identified by re-issuing admin and privileged API calls under low-privilege credentials to test for vertical privilege escalation.
Which CWEs map to API5:2023?
API5:2023 maps to CWE-285, CWE-862, CWE-863.
Does TurboPentest test for Broken Function Level Authorization?
TurboPentest tests authorization and access control dynamically, exercising object-level and function-level checks across privilege boundaries per the OWASP testing guides. Paladin AI chains vulnerabilities to find privilege-escalation paths. Multi-role business-logic depth is where a manual engagement adds a larger context window.
Related OWASP categories
- OWASP API Security Top 10API1:2023: Broken Object Level Authorization
- OWASP API Security Top 10API2:2023: Broken Authentication
- OWASP API Security Top 10API3:2023: Broken Object Property Level Authorization
- OWASP API Security Top 10API4:2023: Unrestricted Resource Consumption
- OWASP API Security Top 10API6:2023: Unrestricted Access to Sensitive Business Flows
- OWASP API Security Top 10API7:2023: Server Side Request Forgery (SSRF)
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest