Skip to content

Hide Navigation Hide TOC

BOLA Cross-User Data Access Attempt (Semantic) - ATR-2026-01614 (7cd8a6f3-e79a-52a9-8215-86357bd1b4d6)

Detects Broken Object Level Authorization (BOLA / IDOR) attempts where an agent is asked to access data belonging to another user—typically by requesting the record with the "highest balance", "most transactions", a specific account number that does not belong to the requester, or by implying knowledge of another user's object ID. Unlike RBAC bypass (which targets role filters), BOLA targets object-level references. Semantic detection is needed because the attack may be phrased as an innocuous-looking query ("get account with balance > 0") without explicit cross-user framing.

Cluster A Galaxy A Cluster B Galaxy B Level
BOLA Cross-User Data Access Attempt (Semantic) - ATR-2026-01614 (7cd8a6f3-e79a-52a9-8215-86357bd1b4d6) Agent Threat Rules Craft Adversarial Data (a7c30122-b393-4265-91b7-57cd1211e3f9) MITRE ATLAS Attack Pattern 1