← Access Control in Depth
ReadingLesson 4 of 5 · 10 min
Understanding privilege escalation
What it is
Privilege escalation is moving from the permissions you hold to ones you do not — a normal user reaching an admin function, one role assuming another's rights. It turns on a control that decides privilege from something the user can influence: a role field in a token, a hidden form value, an endpoint that never re-checks.
How you approach it
- What tells the server your role? A field in a token, a value in your profile, a parameter on the request? Find the thing that says 'user' where it might say 'admin'.
- Change it, or reach the privileged endpoint directly. Admin routes often trust that only admins would ever call them.
- The flag is behind an action only a higher role should perform. Perform it.
How it gets fixed
The application trusted a client-influenced value to decide privilege, or exposed a privileged action that never re-checked the caller's role. Either let an ordinary account act as a higher one. The fix is to derive authorization from server-side state and enforce it on every privileged path.
Practise it
Every lab in the Privilege escalation category drills exactly this. Start at Apprentice and work up.