Broken object-level authorization in the Orders API
- Affected asset
- api.ornek-sirket.com.tr
- Category
- OWASP API1:2023 · CWE-639
- Discovered
- September 12, 2026
- Reported
- Same day, by phone
Impact
A signed-in customer can view invoices that belong to other customers. Because the invoices include names and addresses, this may require notification under KVKK (Turkey’s personal data protection law).
Remediation
In the invoice lookup, verify that the record belongs to the signed-in user. Centralize authorization checks in a single middleware layer and apply it to every endpoint.