Skip to main content
XsiSec.com
HomeReposBlogProjectsPortfolio
© 2026 XsiSec.com
Security rules |security.txt
Updated 2026-08-15 · v1.0.0+2026-08-14.82f92cb · 82f92cb
← Back to overview
Security article

Knowledge article about Access-control

Knowledge article about Access-control: I wanted to make my knowledge more wide so I started ona new topic Access Control Access control vulnerabilities and privilege escalation In this section, we will discuss what access control security is, describe privilege escalation and the types of vulnerabilities that can arise with access control, and summarize how... • Knowledge • Access-control • access-control, knowledge

2023-04-122 tags
Tags

I wanted to make my knowledge more wide so I started ona  new topic Access Control

Access control vulnerabilities and privilege escalation

In this section, we will discuss what access control security is, describe privilege escalation and the types of vulnerabilities that can arise with access control, and summarize how to prevent these vulnerabilities.

The first question..

What is access control?

Access control (or authorization) is the application of constraints on who (or what) can perform attempted actions or access resources that they have requested.  In the context of web applications, access control is dependent on authentication and session management:

  • Authentication identifies the user and confirms that they are who they say they are.
  • Session management identifies which subsequent HTTP requests are being made by that same user.
  • Access control determines whether the user is allowed to carry out the action that they are attempting to perform.

 

Broken access controls are a commonly encountered and often critical security vulnerability.  Design and management of access controls is a complex and dynamic problem that applies business, organizational, and legal constraints to a technical implementation. Access control design decisions have to be made by humans, not technology, and the potential for errors is high.

sql
 From a user perspective, access controls can be divided into the following categories
  • Vertical access controls 
  • Horizontal access controls
  • Context-dependent access controls

 

Vertical access controls

Vertical access controls are mechanisms that restrict access to sensitive functionality that is not available to other types of users.

With vertical access controls, different types of users have access to different application functions.

sql
For example, an administrator might be able to modify or delete any user's account, while an ordinary user has no access to these actions. 

Vertical access controls can be more fine-grained implementations of security models designed to enforce business policies such as separation of duties and least privilege.

Horizontal access controls

Horizontal access controls are mechanisms that restrict access to resources to the users who are specifically allowed to access those resources.

With horizontal access controls, different users have access to a subset of resources of the same type.

sql
For example, a banking application will allow a user to view transactions and make payments from their own accounts, but not the accounts of any other user.

Context-dependent access controls

Context-dependent access controls restrict access to functionality and resources based upon the state of the application or the user's interaction with it.

Context-dependent access controls prevent a user performing actions in the wrong order.

sql
For example, a retail website might prevent users from modifying the contents of their shopping cart after they have made payment.

 

 

Examples of broken access controls

Broken access control vulnerabilities exist when a user can in fact access some resource or perform some action that they are not supposed to be able to access.

 

 

Vertical privilege escalation

If a user can gain access to functionality that they are not permitted to access then this is vertical privilege escalation.

sql
For example, if a non-administrative user can in fact gain access to an admin page where they can delete user accounts, then this is vertical privilege escalation.

 

Unprotected functionality

sql
 At its most basic, vertical privilege escalation arises where an application does not enforce any protection over sensitive functionality. 
For example, administrative functions might be linked from an administrator's welcome page but not from a user's welcome page. 

However, a user might simply be able to access the administrative functions by browsing directly to the relevant admin URL.

For example, a website might host sensitive functionality at the following URL:

https://insecure-website.com/admin

This might in fact be accessible by any user, not only administrative users who have a link to the functionality in their user interface. In some cases, the administrative URL might be disclosed in other locations, such as the robots.txt file:

https://insecure-website.com/robots.txt

Even if the URL isn't disclosed anywhere, an attacker may be able to use a wordlist to brute-force the location of the sensitive functionality.

 

source

Navigate

In this post

  1. 01Access control vulnerabilities and privilege escalation
  2. 02What is access control?
  3. 03Vertical access controls
  4. 04Horizontal access controls
  5. 05Context-dependent access controls
  6. 06Examples of broken access controls
  7. 07Vertical privilege escalation
Search
Explore

Popular tags

Browse all 30 tags

Comments

0 comments

No comments yet — be the first to comment.