Learning paths

AuthZ learning path

18 resources, ordered. Work down the list โ€” each stage assumes the one above it.

Authorization / Broken Access Control

A route through the library rather than a dump of it. Items are drawn from the full AuthZ collection, filtered to teaching material (news items are excluded) and ordered within each stage by depth signals โ€” whether the piece carries code, how substantial it is, and what readers actually open.

1

Start here

5 resources

Orientation and first principles โ€” what the bug class is and how it behaves.

  1. Insecure Direct Object Reference (IDOR) Attack Guide | Hackviser
    7 min readhackviser.com2026
    Guide to Insecure Direct Object Reference (IDOR) vulnerabilities, detailing manual testing techniques across URL parameters, POST bodies, HTTP headers, cookies, and file access. It covers automated discovery using tools like Burp Suite and ffuf, scripting with Python, and various attack vectors including numeric, UUID, hash-based, parameter pollution, and mass assignment bypasses, as well as blind IDOR exploitation.
  2. Preventing broken access control in express Node.js applications
    11 min readsnyk.io2026
    Library detailing broken access control vulnerabilities in Express Node.js applications, covering scenarios like unprotected admin panels, predictable user IDs leading to IDOR, and insecure direct object references. It illustrates how to prevent issues such as vertical privilege escalation and horizontal data exposure, emphasizing the risks of clear text logging and insufficient CSRF protection within Express middleware.
  3. RBAC vs ABAC vs ReBAC: How to Choose Access Control Models
    12 min readdev.to2026
    Library comparing Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), and Relationship-Based Access Control (ReBAC). It details how RBAC, while simple, suffers from "Role Explosion" due to complexity in systems like AWS IAM and Kubernetes. ABAC is presented as a solution, using attributes and dynamic evaluation instead of static roles, exemplified by OPA and AWS IAM's Condition blocks. ReBAC principles are also touched upon, particularly in the context of Azure's resource hierarchy inheritance.
  4. Defending Against Broken Access Control
    10 min readauthgear.com2026
    Library for defending against Broken Access Control (BAC), the #1 threat (A01:2021) in the OWASP Top 10. This vulnerability occurs when applications fail to enforce authorization, allowing unauthorized users to access data or functions. Learn about common attack techniques like Horizontal and Vertical Privilege Escalation, Parameter Tampering, IDOR, Data Exposure, API Abuse, and BOLA. The resource highlights real-world examples such as the Optus data breach and the Kia vehicle control vulnerability, emphasizing the critical need for robust server-side authorization.
  5. Why Broken Access Control Dominates OWASP Top 10 in 2026
    7 min readauth0.com2026
    Library for building secure applications, focusing on mitigating Broken Access Control (BAC) and Broken Object Level Authorization (BOLA). It highlights how traditional SAST and DAST tools struggle with these logic flaws, contrasting them with technical vulnerabilities like SQL Injection. The library advocates for centralized authorization logic using the Policy Decision Point (PDP) and Policy Enforcement Point (PEP) pattern, and promotes Policy as Code (PaC) with tools like Auth0 FGA, OpenFGA, and OPA to manage authorization policies externally from application code.
2

Build depth

5 resources

Real testing methodology, tooling, and writeups that show the work.

  1. Authorization Testing Automation Cheat Sheet - OWASP
    10 min readcheatsheetseries.owasp.org2026
    Cheat sheet offering a methodology for automating authorization tests by formalizing an authorization matrix in XML. This approach enables the creation of integration tests that validate access controls for REST services across different logical roles like ANONYMOUS, BASIC, and ADMIN. The process involves defining roles, services with their associated permissions, and test payloads to ensure new feature additions or modifications do not conflict with existing authorization definitions.
  2. Authorization Cheat Sheet - OWASP
    18 min readcheatsheetseries.owasp.org2026
    Cheatsheet providing guidance for robust authorization logic, addressing concerns like Broken Access Control, a top OWASP 2021 vulnerability. It details implementing "Least Privileges" by granting only necessary permissions and adopting a "Deny by Default" approach for all requests, emphasizing the need for validation on every interaction to prevent unauthorized access to resources, which can impact confidentiality, integrity, and availability.
  3. Ask the Agent Nicely: Two Authorization Bypasses in n8n AI Agents
    8 min readdeturris.io2026
    Writeup on CVE-2026-65015 and CVE-2026-59207 detailing two authorization bypasses in n8n AI Agents. The first, CVE-2026-65015, allows a read-only Project Viewer to execute arbitrary n8n nodes, including exfiltrating credentials and potentially executing host commands. The second, CVE-2026-59207, bypasses the "Allowed HTTP Request Domains" restriction for credentials via the MCP client, enabling credential exfiltration.
  4. Uncontrolled Access Control: Compromising Paxton10
    6 min readtechanarchy.net2026
    Writeup detailing a chain of vulnerabilities in the Paxton10 access control system that enables unauthenticated, network-adjacent attackers to achieve operating system command execution. The exploitation involves leveraging hardcoded credentials for the nginx diagnostic portal, extracting plaintext bearer tokens from access logs, and exploiting an SQL injection vulnerability in the lost tokens event search. This SQL injection leads to command execution via `xp_cmdshell`, which is unconditionally enabled and accessible due to the sysadmin role granted to service accounts.
  5. Local Privilege Escalation To System In Wibu-Systems CodeMeter Application
    8 min readshelltrail.com2026
    Library for privilege escalation targeting Wibu-Systems CodeMeter. This library details a method to achieve SYSTEM privileges from a low-privileged session by leveraging CodeMeter's `cmu.exe` to create files under `C:\CM-Stick`. Through a directory symlink hijack, this capability becomes an arbitrary file delete. Combined with the `::\$INDEX_ALLOCATION` NTFS trick and the Windows Installer's `C:\Config.Msi` rollback technique, it enables a full local privilege escalation to SYSTEM.
3

Go deep

8 resources

Novel research, edge cases, and the techniques that push the class forward.

  1. Security Benchmarking Authorization Policy Engines: Rego, Cedar, OpenFGA
    9 min readgoteleport.com2026
    Framework for dynamically evaluating authorization policy engines, including Rego, Cedar, OpenFGA, and Teleport ACD. This system automates security benchmarking and robustness testing by executing predefined test cases in isolated Docker containers for each engine, comparing actual results against expected outcomes to identify potential threats and vulnerabilities.
  2. How I Found a $113,337 AF_ALG Linux Local Privilege Escalation Before Copy Fail
    17 min readidnsec.com2026
    Library detailing the discovery and exploitation of CVE-2025-39964, a Linux AF_ALG local privilege escalation vulnerability. This research uncovered an out-of-bounds access flaw in the kernel's handling of user-supplied data for cryptographic operations, allowing unprivileged users to gain root access and escape Docker containers. The vulnerability, present since 2011, stems from a race condition between writers sharing an AF_ALG socket, distinct from the later disclosed "Copy Fail" bug.
  3. AI Agent Authorization Beyond Authentication: A Look At AWS Dogwood
    12 min readblog.gitguardian.com2026
    Library for AI agent authorization, AWS Dogwood, builds on Cedar to incorporate temporal policy, evaluating sequences of prior actions beyond point-in-time requests for tool calls. This temporal policy addresses risks from sequences of seemingly benign actions, such as the "lethal trifecta" of reading sensitive files and then exfiltrating them. GitGuardian's Secret Analyzer provides permission context and the Exploration Map traces consumers and resources, aiding migration from long-lived secrets as AI-related leaks grew significantly.
  4. Privilege escalation from IIS AppPool to NT Authority/SYSTEM via AD CS RPC endpoint
    2 min readmannulinux.org2026
    Technique detailing privilege escalation from IIS AppPool to NT Authority\SYSTEM within an Active Directory domain. This method leverages a Windows behavior where IIS AppPool identities accessing network resources are elevated to the host's machine account. The technique involves submitting a Certificate Signing Request to the Active Directory Certificate Services (AD CS) RPC endpoint, obtaining a machine account certificate, and then using the S4U2Self technique with tools like Rubeus to impersonate administrator accounts.
  5. Leveraging undocumented CodeConnection APIs in a CodePipeline build job or SageMaker Studio Notebook to enumerate, clone, push and delete code repositories.
    14 min readthomaspreece.com2026
    Library detailing privilege escalation techniques within AWS CodePipeline and SageMaker Studio. It explains how an improperly configured "Full clone" output artifact format for CodeConnections, combined with insufficient IAM role restrictions, allows attackers to enumerate, clone, push, and delete repositories from the source code provider. The library specifically covers the use of undocumented CodeConnection APIs and the implications of the `codeconnections:UseConnection` and `codestar-connections:UseConnection` IAM permissions.
  6. The skb that wasn't freed - the Fragnesia primitive via Open vSwitch
    19 min readblog.doyensec.com2026
    Tool for privilege escalation exploiting the Fragnesia primitive in Open vSwitch. This vulnerability, tracked as CVE-2026-90049, CVE-2026-89487, and CVE-2026-80977, arises when Open vSwitch incorrectly strips the `SKBFL_SHARED_FRAG` marker from packets, allowing unprivileged users to overwrite read-only memory mappings and achieve local privilege escalation on affected distributions with user namespaces enabled.
  7. Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454
    9 min readdavidcarliez.github.io2026
    Writeup details a Local Privilege Escalation (LPE) technique in Windows, bypassing User Account Control (UAC) by exploiting a missing authorization check in `Windows.Internal.AppResolver.AppResolverActivationArgsFactory`. An attacker can leverage a zero-capability AppContainer to register a malicious handler for `ms-settings:`, which is then auto-elevated via `fodhelper.exe` using the administrator's token, ultimately leading to a SYSTEM-privileged process. This technique is associated with CVE-2026-50454, though the author notes it differs from the publicly described relative path traversal vulnerability.
  8. Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking
    12 min readinfosecwriteups.com2026
    Library for Confused Deputy exploit in Google IdP, enabling universal account takeover via device code flow hijacking. This vulnerability allows an attacker to silently steal an access token for an arbitrary Google-registered client, bypassing consent screens and 2FA, by chaining two bugs: session transferability via a crafted URL and the authorization serverโ€™s failure to bind `client_id` and `scope` server-side to the `device_code`. The initial report to Google's VRP was initially rejected but later fixed after a one-click Proof of Concept was developed.