Post cover image

September 21, 2026

BOLA in the Wild: Reading Another User’s Full Profile by Changing One UUID

CWE-639: Authorization Bypass Through User-Controlled Key CWE-284: Improper Access Control CVSS 3.1: 6.5 (Medium) —…

By Neel Chauhan

2 min read