Access Control: Multi User Access Control¶
Identifier:
multi_user_access_control
Scanner Support¶
| GraphQL Scanner | REST Scanner | WebApp Scanner | ASM Scanner | Automated Pentest |
|---|---|---|---|---|
Description¶
Multi-user access control vulnerabilities occur when systems fail to properly separate access between users, roles, or tenants, allowing unauthorized access or modification due to flawed authorization logic.
How we test: We replay the same requests with different authenticated users and compare responses to detect broken access control across user scopes (cross-tenant and RBAC/privilege boundaries).
Prerequisites:
- The scan must include at least two authenticated users.
- The target must expose readable or writable operations with parameters that can be compared across user scopes.
- Denylisted paths are skipped.
By default, when no configuration is provided, the check will cover all paths and keys matching. Response similarity will be used to detect isolation violations.
References:
Configuration¶
Example¶
Example configuration:
---
security_tests:
multi_user_access_control:
keys_matching:
- card_number
main_user: ''
natural_language_rule: Ensure that a user's notes cannot be accessed by other
users.
other_users:
detect:
- if: request.is_authenticated
is: true
is_not: null
- if: helpers.fingerprints.same
is: true
is_not: null
paths:
- /users/{id}
skip: false
specific_users: {}
Reference¶
For detector options, see the Custom Rules Reference.
keys_matching¶
Type: List[string]
List of keys in a response body that will be compared between different users, to detect an isolation violation.
If the key values are the exact same between these users, an alert will be raised.
For example if you want to control the key card_number, you can use the following:
main_user¶
Type: string
The baseline user for the check. Escape compares this user with the other configured users to detect isolation violations.
natural_language_rule¶
Type: string
A natural language prompt to describe what should be checked for multi-user access control. This will be used to generate the rules to detect multi-user access control issues when analyzing the responses. You can review the generated rules in the alert details.
other_users¶
Type: MultiUserAccessControlRule
The conditions to trigger the alert when comparing the original and switched responses. The list of conditions are combined with AND logic by default. By default, the conditions check if the request is authenticated and if the responses of both users have the same fingerprint.
paths¶
Type: List[string]
List of paths that this check will cover. Add * to cover all paths.
For example if you want to control the path /users/{id}, you can use the following:
To cover all paths, you can use the following:
skip¶
Type: boolean
Skip the test if true.
specific_users¶
Type: Dict[string, MultiUserAccessControlRule]
The conditions to trigger the alert when analyzing the responses between a given user and specific users. The list of conditions are combined with AND logic by default.
MultiUserAccessControlRule¶
detect¶
Type: List[APILogicalAndDetector|APILogicalNotDetector|APILogicalOrDetector|FingerprintCountDetector|FingerprintsSameDetector|HelpersRequestCrudDetector|HelpersResponseIsSuccessfulDetector|JSONMatchesAllDetector|JSONMatchesCountDetector|RegexMatchesAllDetector|RegexMatchesCountDetector|RequestBodyJSONDetector|RequestBodyTextDetector|RequestHeadersDetector|RequestIsAuthenticatedDetector|RequestMethodDetector|RequestObjectDetector|RequestUserDetector|ResponseBodyJSONDetector|ResponseBodyTextDetector|ResponseDurationDetector|ResponseHeadersDetector|ResponseObjectDetector|ResponseStatusCodeDetector|ScanTypeDetector|SchemaNeedAuthenticationDetector|SchemaPathRefDetector|SchemaUrlDetector|VariableDefinedDetector]*
The detectors to trigger the alert when analyzing the responses between the main user and other users.