---
description: Detect endpoints at risk of Broken Object Level Authorization attacks.
title: Broken Object Level Authorization vulnerability detection
image: https://developers.cloudflare.com/api-shield/security/bola-vulnerability-detection/og.png?v=fd62015f645a0c05
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/api-shield/llms.txt  
> Use this file to discover all available pages before exploring further.

# Broken Object Level Authorization vulnerability detection

Last updated Sep 29, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/api-shield/security/bola-vulnerability-detection/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

A Broken Object Level Authorization (BOLA) vulnerability is where an application or API fails to properly verify if a user has permission to access specific data.

Bugs in the application or API allow attackers to bypass authorization checks and access potentially sensitive information by manipulating and iterating through object identifiers (such as user IDs or order IDs).

Vulnerabilities can occur at any time, including in the original application's deployment. However, changes or upgrades to authentication and authorization policies can also introduce these bugs.

BOLA vulnerabilities are as dangerous as an account takeover. Successfully exploiting a BOLA vulnerability allows the attacker to access or change data that they should not have ownership over.

Cloudflare labels endpoints with BOLA risk when it detects two distinct signals common with attacks exploiting BOLA: **Parameter pollution** and **Enumeration**.

## Enumeration

Cloudflare estimates how many distinct combinations of all path-parameter values each session with a configured session identifier requests from an endpoint. It compares each session's count with the distribution observed for the same endpoint.

Note

Sessions that have more random behavior or repetition have a higher chance of triggering an alert.

The BOLA enumeration label requires more than approximately 10,000 sessions with a configured session identifier and at least one path-parameter value during the seven-day detection window before an endpoint is eligible for outlier detection.

<details>

<summary>

Enumeration example

</summary>

**Endpoint**: <code>GET /api/v1/users/{userId}/credit-cards</code>

- **Normal behavior**: Users request credit cards using only their own <code>userId</code>.
- **Attack behavior**: Attackers request hundreds of <code>userId</code> values per session by brute-force iterating through <code>userIds</code> found via other methods.
- **Result**: If the origin authorization policy is broken for this endpoint, the attacker gains credit card information on every user account they request it for.

</details>

## Parameter pollution

Cloudflare detects requests with an HTTP response status below `400` where the same parameter appears both in a schema-defined location (path, query string, header, or cookie) and in an unexpected request location, with different values in each location. API Shield applies a risk label only when the resulting pattern meets the detector's anomaly criteria.

<details>

<summary>

Parameter pollution example

</summary>

**Endpoint**: <code>GET /api/v1/orders/{orderId}</code>

- **Normal behavior**: <code>orderId</code> sent in a path variable like <code>GET /api/v1/orders/12345</code>
- **Attacker behavior**: <code>orderId</code> is also sent as a query parameter, triggering old, undocumented code that looks for orders in the query parameter and happens to lack an authorization check: <code>GET /api/v1/orders/12345?orderId=67890</code>
- **Result**: By passing in a fake order or an order that the attacker owns (<code>12345</code>), they are able to trigger the old, undocumented code and access an order that they do not own (<code>67890</code>)

</details>

## Process

API Shield detects BOLA attacks by learning visitor traffic patterns and identifying anomalous access to specific objects. Affected endpoints are automatically labeled with the following [risk labels](https://developers.cloudflare.com/api-shield/management-and-monitoring/endpoint-labels/#risk-labels):

- `cf-risk-bola-enumeration`: Automatically added when some sessions request unusually many distinct combinations of path parameter values for an endpoint compared with other sessions.
- `cf-risk-bola-pollution`: Automatically added when Cloudflare detects an unusual pattern of requests that send different values for the same parameter in its schema-defined location and an unexpected request location. Only requests whose responses have status codes below `400` contribute.

If you see one of these labels on your API endpoints, check its authorization policy with your developer team to find any authorization bugs. You can also contact Cloudflare for a report including attacker identifiers to confirm attack reach and impact.

BOLA attack information can be found in your [Security Overview](#security-overview), [Security Analytics](#security-analytics), and [Endpoint details](#endpoint-details).

### Security Overview

If BOLA vulnerabilities have been detected on your endpoints, you can view a summary of the attack and suggestions to mitigate it via the Cloudflare dashboard.

1. In the Cloudflare dashboard, go to the **Security** page. [Go to **Overview** ↗](https://dash.cloudflare.com/?to=/:account/:zone/security/overview)
2. Go to **API abuse** or **All suggestions**.
3. Depending on the type of attack, select **Review traffic from potential BOLA enumeration attack** or **Review traffic from potential parameter pollution attack** to view details of the attack and suggested actions.
4. Select **View all affected endpoints** or **View details** on a specific endpoint to review suspicious sessions in [Web Assets](#endpoint-details).

Cloudflare evaluates your session requests for both enumeration and parameter pollution attacks and provides you with a list of at-risk endpoints and the number of anomalous sessions where an attack was detected. You can follow the suggested actions to address your BOLA vulnerabilities and prevent future attacks against your endpoints.

Note

If the insight has been archived but attacks are still present, you can filter by **Show archived**.

### Security Analytics

You can view analytics of your zone's traffic profile and suspicious requests associated with enumeration or parameter pollution attacks in the Cloudflare dashboard.

[Go to **Analytics** ↗](https://dash.cloudflare.com/?to=/:account/:zone/security/analytics)

Filter requests by the hashed session IDs shown in the detection and the corresponding BOLA vulnerability risk label. Security Analytics queries adaptively sampled request data for the combined detection period of the selected reports.

Note

API Shield creates each hashed session ID from the combined traffic values selected by your configured session identifiers. The displayed ID is not a configured selector or a raw traffic value.

The Security Analytics insight considers up to 50 reports per BOLA detection type whose detection periods ended within the previous seven days and up to 50 sessions from each report. Its filters are not limited by operation ID, so they can include sampled requests from the selected sessions to other operations carrying the same BOLA risk label.

Review the top statistics and details of managed API endpoints, paths and values targeted by the attack, source IPs, source user agents, and source fingerprints.

Review your traffic profile for unusual patterns, such as spikes in unique object requests or unexpected parameter locations.

### Endpoint details

You can expand the endpoint details in Web Assets to access information on suspicious sessions' activity on the endpoint, including both enumeration attack and parameter pollution attack details.

[Go to **Web assets** ↗](https://dash.cloudflare.com/?to=/:account/:zone/security/web-assets)

Under **Security overview**, select **View attack** to review affected sessions with associated IP addresses and JA4 fingerprints (TLS client fingerprints that help identify the software making the request).

You can export the `.csv` file containing all the IP addresses and JA4 fingerprints for all or only a specific session.

The details specify the parameter that was affected, the number of sessions involved in the attack, and how far their behavior deviated from baseline.

If unauthorized access to the parameter was obtained, consider the potential impact to your application, users, and data. As a best practice, consult with your application and API developers to confirm unauthorized access by reviewing your API origin logs for the IP address and JA4 fingerprint of the abusive sessions.

You can view attack data in [Security Analytics](#security-analytics).

[Go to **Analytics** ↗](https://dash.cloudflare.com/?to=/:account/:zone/security/analytics)

The link from endpoint details filters Security Analytics by the managed operation and the report's detection period. You can also filter by suspicious IP addresses and fingerprints found in the attack details.

---

## Availability

Broken Object Level Authorization vulnerability detection is only available for Enterprise customers. If you are an Enterprise customer interested in this product, contact your account team.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/api-shield/security/bola-vulnerability-detection/#page","headline":"Broken Object Level Authorization vulnerability detection","description":"Detect endpoints at risk of Broken Object Level Authorization attacks.","url":"https://developers.cloudflare.com/api-shield/security/bola-vulnerability-detection/","inLanguage":"en","image":"https://developers.cloudflare.com/api-shield/security/bola-vulnerability-detection/og.png?v=fd62015f645a0c05","dateModified":"2026-09-29","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```
