Skip to main content

Glossary

Broken Access Control

A vulnerability class in which an application fails to properly enforce restrictions on what authenticated users are allowed to do, letting them view or modify data or functionality outside their permissions. It has topped the OWASP Top 10 list of web application security risks in recent years.

← All 285 glossary terms