← Access Control in Depth
ReadingLesson 4 of 5 · 10 min

Understanding privilege escalation

What it is

Privilege escalation is moving from the permissions you hold to ones you do not — a normal user reaching an admin function, one role assuming another's rights. It turns on a control that decides privilege from something the user can influence: a role field in a token, a hidden form value, an endpoint that never re-checks.

How you approach it

  1. What tells the server your role? A field in a token, a value in your profile, a parameter on the request? Find the thing that says 'user' where it might say 'admin'.
  2. Change it, or reach the privileged endpoint directly. Admin routes often trust that only admins would ever call them.
  3. The flag is behind an action only a higher role should perform. Perform it.

How it gets fixed

The application trusted a client-influenced value to decide privilege, or exposed a privileged action that never re-checked the caller's role. Either let an ordinary account act as a higher one. The fix is to derive authorization from server-side state and enforce it on every privileged path.

Practise it

Every lab in the Privilege escalation category drills exactly this. Start at Apprentice and work up.

← Lab: mass-assigning into an admin group
Sign in to track thisLab: the role field the client should not set →