M3:2024: Insecure Authentication/Authorization
Authentication and authorization performed client-side, weak or bypassable biometric checks, or server-side APIs that trust the mobile client instead of enforcing authorization on every request.
How it's found
Found by replaying authenticated mobile API traffic to test session handling, biometric bypass, and whether authorization is enforced server-side.
Standards mapping
How TurboPentest tests for this
TurboPentest tests authentication dynamically, following the OWASP testing guides across login, session, and multi-factor flows to find bypasses and weak credential handling. Paladin AI chains findings across requests to surface multi-step authentication weaknesses. A manual IntegSec engagement applies deeper methodology.
Tools: Paladin AI, Web Scanner
Frequently asked questions
What is M3:2024 Insecure Authentication/Authorization?
Authentication and authorization performed client-side, weak or bypassable biometric checks, or server-side APIs that trust the mobile client instead of enforcing authorization on every request.
How do you find Insecure Authentication/Authorization?
Found by replaying authenticated mobile API traffic to test session handling, biometric bypass, and whether authorization is enforced server-side.
Which CWEs map to M3:2024?
M3:2024 maps to CWE-287, CWE-285, CWE-306.
Does TurboPentest test for Insecure Authentication/Authorization?
TurboPentest tests authentication dynamically, following the OWASP testing guides across login, session, and multi-factor flows to find bypasses and weak credential handling. Paladin AI chains findings across requests to surface multi-step authentication weaknesses. A manual IntegSec engagement applies deeper methodology.
Related OWASP categories
- OWASP Mobile Top 10M1:2024: Improper Credential Usage
- OWASP Mobile Top 10M2:2024: Inadequate Supply Chain Security
- OWASP Mobile Top 10M4:2024: Insufficient Input/Output Validation
- OWASP Mobile Top 10M5:2024: Insecure Communication
- OWASP Mobile Top 10M6:2024: Inadequate Privacy Controls
- OWASP Mobile Top 10M7:2024: Insufficient Binary Protections
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest