Skip to content

Hide Navigation Hide TOC

SQL Injection Tautology RBAC Bypass - ATR-2026-01600 (4803d364-f5c2-52e4-bb7a-c41937c0e989)

Detects SQL injection tautology patterns embedded in agent tool arguments that attempt to bypass row-level security or RBAC filters. Tautologies such as "OR 1=1", "OR true", "OR 'a'='a'" cause the WHERE clause to always evaluate to true, returning all rows regardless of the caller's authorization scope. This is the primary SQL-based BOLA / broken-object-level-authorization vector targeting AI agents that forward user-supplied values directly into database queries.

Cluster A Galaxy A Cluster B Galaxy B Level
SQL Injection Tautology RBAC Bypass - ATR-2026-01600 (4803d364-f5c2-52e4-bb7a-c41937c0e989) Agent Threat Rules Exploit Public-Facing Application - T1190 (3f886f2a-874f-4333-b794-aa6075009b1c) Attack Pattern 1
SQL Injection Tautology RBAC Bypass - ATR-2026-01600 (4803d364-f5c2-52e4-bb7a-c41937c0e989) Agent Threat Rules Craft Adversarial Data (a7c30122-b393-4265-91b7-57cd1211e3f9) MITRE ATLAS Attack Pattern 1