Broken Object Level Authorization in the Wild: First Large-Scale Empirical Taxonomy from 107 Bug Bounty Reports
arXiv·medium signal
Presents one of the first large-scale empirical analyses of BOLA (the #1 OWASP API vulnerability) from 107 classified HackerOne disclosures (2021-2026). Builds a reproducible taxonomy of real-world BOLA patterns, moving beyond conceptual descriptions to concrete attack patterns. Directly useful for API security reviews and threat modeling.