top of page
< Back

BFLA

BFLA occurs when APIs expose privileged functions without proper authorization checks, enabling attackers to execute admin-level or restricted operations directly.

Function Endpoint Called → Privileged Action Triggered → Authorization Missing → Admin Action Executed → Function Protected

bottom of page