SecSmithOps
All posts
Application SecurityJune 2, 20266 min read

Why Automated Scanners Keep Missing Authorization Flaws

Automated scanners are good at pattern matching known vulnerability signatures — a reflected parameter, a missing header, an outdated library. They are much weaker at reasoning about business logic, and authorization is almost entirely business logic.

A broken object-level authorization (BOLA) flaw doesn't look wrong to a scanner: the request is well-formed, the response is a 200, and the payload parses cleanly. The only thing wrong is that the record returned doesn't belong to the requesting user — and a scanner has no concept of 'belongs to'.

When we review an application manually, we build a map of every resource identifier and cross-reference it against every role that can reach the endpoint that returns it. That mapping exercise is what surfaces the gap — not a longer scan.

The practical takeaway for engineering teams: treat authorization checks as a first-class, centrally-tested concern, not something re-implemented per endpoint. It's the difference between fixing a class of bug once and finding a new instance of it every quarter.