Why Automated Scanners Keep Missing Authorization Flaws
Automated scanners are good at pattern matching known vulnerability signatures — a reflected parameter, a missing header, an outdated library. They are much weaker at reasoning about business logic, and authorization is almost entirely business logic.
A broken object-level authorization (BOLA) flaw doesn't look wrong to a scanner: the request is well-formed, the response is a 200, and the payload parses cleanly. The only thing wrong is that the record returned doesn't belong to the requesting user — and a scanner has no concept of 'belongs to'.
When we review an application manually, we build a map of every resource identifier and cross-reference it against every role that can reach the endpoint that returns it. That mapping exercise is what surfaces the gap — not a longer scan.
The practical takeaway for engineering teams: treat authorization checks as a first-class, centrally-tested concern, not something re-implemented per endpoint. It's the difference between fixing a class of bug once and finding a new instance of it every quarter.