research / arXiv:2605.25865 · 25 May 2026
Broken Object Level Authorization in the Wild: An Empirical Taxonomy from 100+ Bug Bounty Disclosures
Abstract
An empirical analysis of BOLA in public bug bounty reports. From 200 HackerOne disclosures tagged IDOR or Improper Access Control (2021–2026), 107 were fully classified into a six-family taxonomy. 78.5% were confirmed in-scope BOLA; action-level object BOLA accounts for 41.7% of confirmed cases; 21.5% fall outside strict BOLA criteria, suggesting platform tag counts inflate BOLA measurements. Also documents an 11.9% vertical privilege-escalation rate and recurring GraphQL Global ID exploitation patterns.
200 sampled → 107 classified → 84 confirmed
Key findings
- 200 HackerOne disclosures tagged IDOR or Improper Access Control (2021–2026) sampled; 107 fully classified.
- 78.5% (84 of 107) confirmed as in-scope BOLA, across a six-family taxonomy.
- Action-level object BOLA, unauthorised state changes on other users’ objects, is 41.7% of confirmed cases.
- 21.5% of tagged reports fail strict BOLA criteria, so platform tag counts overstate BOLA.
- 11.9% involve vertical privilege escalation; GraphQL Global ID exploitation recurs.
Read and cite
arXiv·PDF·doi:10.48550/arXiv.2605.25865·Blog summary (APISec Research Labs)
@misc{kaur2026bola,
title = {Broken Object Level Authorization in the Wild: An Empirical Taxonomy from 100+ Bug Bounty Disclosures},
author = {Kaur, Bandana},
year = {2026},
eprint = {2605.25865},
archivePrefix = {arXiv},
doi = {10.48550/arXiv.2605.25865},
url = {https://arxiv.org/abs/2605.25865}
}