Skip to content

What is BFLA?

Broken function level authorisation, or BFLA, is when an API lets a caller use a function they should not have, such as an ordinary user calling an administrative endpoint. BOLA is about the wrong data; BFLA is about the wrong action.

How it works

A support portal shows its admin buttons only to admins. The API behind it never checks the caller’s role:

GET    /api/users/me              → 200  (ordinary user, correct)
DELETE /api/admin/users/1093      → 200  (ordinary user, should be 403)

An ordinary user reads the front-end code, finds the admin routes and calls them directly with their own token. The API deletes the account.

A second form uses the HTTP method. A read-only GET /api/invoices/77 is also accepted as PUT, or with an X-HTTP-Method-Override: DELETE header. The function behind it never checks whether this caller may change invoices.

BFLA is listed as API5 in the OWASP API Security Top 10 (2023).

Why classic controls miss it

  • The request is authenticated, well formed and carries no attack payload for a firewall to match.
  • Hiding a button in the interface is not access control. The API stays callable by anyone with a token.
  • Admin and user routes often share one gateway and one token format, so the edge sees nothing unusual.
  • Role checks drift. A new endpoint ships without one, and nothing fails until someone calls it.

How to detect and prevent it

  1. Deny by default. Every function needs an explicit role or permission, checked on the server.
  2. Separate administrative functions onto their own routes or services, with their own authorisation policy.
  3. Refuse method overrides you do not need, and check the role for every method an endpoint accepts.
  4. Test every endpoint with every role. An ordinary user calling an admin function must receive 403.
  5. Alert on any call from a non-admin identity to an admin route. One is enough to investigate.

How Cyron handles it

Cyron API Security flags access to functions you mark as restricted and method-override attempts, and reports them under API5 of the OWASP API Security Top 10 (2023). It discovers your APIs passively from live traffic, so admin routes nobody documented still appear in the inventory. When an attack is confirmed, iris, the eBPF kernel agent, blocks the source at the kernel. Explore Cyron API Security.