hackwither_

research / arXiv:2605.25865 · 25 May 2026

Broken Object Level Authorization in the Wild: An Empirical Taxonomy from 100+ Bug Bounty Disclosures

Abstract

An empirical analysis of BOLA in public bug bounty reports. From 200 HackerOne disclosures tagged IDOR or Improper Access Control (2021–2026), 107 were fully classified into a six-family taxonomy. 78.5% were confirmed in-scope BOLA; action-level object BOLA accounts for 41.7% of confirmed cases; 21.5% fall outside strict BOLA criteria, suggesting platform tag counts inflate BOLA measurements. Also documents an 11.9% vertical privilege-escalation rate and recurring GraphQL Global ID exploitation patterns.

107 classified reports: 35 action-level object BOLA, 49 other BOLA families, 23 outside strict criteria84 confirmed BOLA · 78.5%23 out
Fig. 2 The 107 classified reports, one square each. Pink: action-level object BOLA (35 of 84 confirmed). Solid: the other confirmed families. Outlined: outside strict BOLA criteria.

200 sampled → 107 classified → 84 confirmed

Key findings

  1. 200 HackerOne disclosures tagged IDOR or Improper Access Control (2021–2026) sampled; 107 fully classified.
  2. 78.5% (84 of 107) confirmed as in-scope BOLA, across a six-family taxonomy.
  3. Action-level object BOLA, unauthorised state changes on other users’ objects, is 41.7% of confirmed cases.
  4. 21.5% of tagged reports fail strict BOLA criteria, so platform tag counts overstate BOLA.
  5. 11.9% involve vertical privilege escalation; GraphQL Global ID exploitation recurs.

Read and cite

@misc{kaur2026bola,
  title         = {Broken Object Level Authorization in the Wild: An Empirical Taxonomy from 100+ Bug Bounty Disclosures},
  author        = {Kaur, Bandana},
  year          = {2026},
  eprint        = {2605.25865},
  archivePrefix = {arXiv},
  doi           = {10.48550/arXiv.2605.25865},
  url           = {https://arxiv.org/abs/2605.25865}
}