Log in Join
[LOW] · Intigriti · Resolved Duplicate

BFLA ---- on GraphQL ListAvailableRoles query allows unauthorize access to low privileged user

Mohamed El-Fiky {Ghaziroot} Mohamed El-Fiky {Ghaziroot} Web application 26 Aug 2026

The affected asset is anonymised at the researcher's request.

Summary

The GraphQL endpoint cloud.digitalocean.com/graphql is vulnerable to Broken Function Level Authorization (BFLA). A user with low-level privileges (e.g., Billing role) can successfully execute the ListAvailableRoles query, which should be restricted to administrators or users with team management permissions. This allows the disclosure of sensitive custom role metadata, including names, UUIDs, and granular permissions.


Impact

Violation of Least Privilege: A billing user should not have visibility into the security configurations or custom RBAC (Role-Based Access Control) structures of the organization.