Skip to content

Access Control: Multi User Access Control

Identifier: multi_user_access_control

Scanner Support

GraphQL Scanner REST Scanner WebApp Scanner ASM Scanner Automated Pentest

Description

Multi-user access control vulnerabilities occur when systems fail to properly separate access between users, roles, or tenants, allowing unauthorized access or modification due to flawed authorization logic.

How we test: We replay the same requests with different authenticated users and compare responses to detect broken access control across user scopes (cross-tenant and RBAC/privilege boundaries).

Prerequisites:

  • The scan must include at least two authenticated users.
  • The target must expose readable or writable operations with parameters that can be compared across user scopes.
  • Denylisted paths are skipped.

By default, when no configuration is provided, the check will cover all paths and keys matching. Response similarity will be used to detect isolation violations.

References:

Configuration

Example

Example configuration:

---
security_tests:
  multi_user_access_control:
    keys_matching:
    - card_number
    main_user: ''
    natural_language_rule: Ensure that a user's notes cannot be accessed by other
      users.
    other_users:
      detect:
      - if: request.is_authenticated
        is: true
        is_not: null
      - if: helpers.fingerprints.same
        is: true
        is_not: null
    paths:
    - /users/{id}
    skip: false
    specific_users: {}

Reference

For detector options, see the Custom Rules Reference.

keys_matching

Type: List[string]

List of keys in a response body that will be compared between different users, to detect an isolation violation.

If the key values are the exact same between these users, an alert will be raised.

For example if you want to control the key card_number, you can use the following:

---
security_tests:
  multi_user_access_control:
    keys_matching:
    - card_number

main_user

Type: string

The baseline user for the check. Escape compares this user with the other configured users to detect isolation violations.

---
security_tests:
  multi_user_access_control:
    main_user: user1

natural_language_rule

Type: string

A natural language prompt to describe what should be checked for multi-user access control. This will be used to generate the rules to detect multi-user access control issues when analyzing the responses. You can review the generated rules in the alert details.

other_users

Type: MultiUserAccessControlRule

The conditions to trigger the alert when comparing the original and switched responses. The list of conditions are combined with AND logic by default. By default, the conditions check if the request is authenticated and if the responses of both users have the same fingerprint.

paths

Type: List[string]

List of paths that this check will cover. Add * to cover all paths.

For example if you want to control the path /users/{id}, you can use the following:

---
security_tests:
  multi_user_access_control:
    paths:
    - /users/{id}

To cover all paths, you can use the following:

---
security_tests:
  multi_user_access_control:
    paths:
    - '*'

skip

Type: boolean

Skip the test if true.

specific_users

Type: Dict[string, MultiUserAccessControlRule]

The conditions to trigger the alert when analyzing the responses between a given user and specific users. The list of conditions are combined with AND logic by default.

MultiUserAccessControlRule

detect

Type: List[APILogicalAndDetector|APILogicalNotDetector|APILogicalOrDetector|FingerprintCountDetector|FingerprintsSameDetector|HelpersRequestCrudDetector|HelpersResponseIsSuccessfulDetector|JSONMatchesAllDetector|JSONMatchesCountDetector|RegexMatchesAllDetector|RegexMatchesCountDetector|RequestBodyJSONDetector|RequestBodyTextDetector|RequestHeadersDetector|RequestIsAuthenticatedDetector|RequestMethodDetector|RequestObjectDetector|RequestUserDetector|ResponseBodyJSONDetector|ResponseBodyTextDetector|ResponseDurationDetector|ResponseHeadersDetector|ResponseObjectDetector|ResponseStatusCodeDetector|ScanTypeDetector|SchemaNeedAuthenticationDetector|SchemaPathRefDetector|SchemaUrlDetector|VariableDefinedDetector]*

The detectors to trigger the alert when analyzing the responses between the main user and other users.