Breaking Access Control: Logic Manipulation & Role Escalation (Part 2)
📰 Medium · Cybersecurity
After exploring path manipulation, we move into the core of web vulnerabilities: Business Logic Manipulation and Role Escalation. This is… Continue reading on Medium »
Full Article
Title: Breaking Access Control: Logic Manipulation & Role Escalation (Part 2)
URL Source: https://medium.com/@hdhffxfg/breaking-access-control-logic-manipulation-role-escalation-part-2-dce5cc44c909?source=rss------cybersecurity-5
Published Time: 2026-06-14T21:53:54Z
Markdown Content:
[Sitemap](https://medium.com/sitemap/sitemap.xml)
[Open in app](https://play.google.com/store/apps/details?id=com.medium.reader&referrer=utm_source%3DmobileNavBar&source=post_page---top_nav_layout_nav-----------------------------------------)
Sign up
[Sign in](https://medium.com/m/signin?operation=login&redirect=https%3A%2F%2Fmedium.com%2F%40hdhffxfg%2Fbreaking-access-control-logic-manipulation-role-escalation-part-2-dce5cc44c909&source=post_page---top_nav_layout_nav-----------------------global_nav------------------)
[](https://medium.com/?source=post_page---top_nav_layout_nav-----------------------------------------)
Get app
[Write](https://medium.com/m/signin?operation=register&redirect=https%3A%2F%2Fmedium.com%2Fnew-story&source=---top_nav_layout_nav-----------------------new_post_topnav------------------)
[Search](https://medium.com/search?source=post_page---top_nav_layout_nav-----------------------------------------)
Sign up
[Sign in](https://medium.com/m/signin?operation=login&redirect=https%3A%2F%2Fmedium.com%2F%40hdhffxfg%2Fbreaking-access-control-logic-manipulation-role-escalation-part-2-dce5cc44c909&source=post_page---top_nav_layout_nav-----------------------global_nav------------------)

# Breaking Access Control: Logic Manipulation & Role Escalation (Part 2)
[](https://medium.com/@hdhffxfg?source=post_page---byline--dce5cc44c909---------------------------------------)
[Yassin Hamada](https://medium.com/@hdhffxfg?source=post_page---byline--dce5cc44c909---------------------------------------)
Follow
3 min read
·
Jun 14, 2026
[](https://medium.com/m/signin?actionUrl=https%3A%2F%2Fmedium.com%2F_%2Fvote%2Fp%2Fdce5cc44c909&operation=register&redirect=https%3A%2F%2Fmedium.com%2F%40hdhffxfg%2Fbreaking-access-control-logic-manipulation-role-escalation-part-2-dce5cc44c909&user=Yassin+Hamada&userId=0099af262952&source=---header_actions--dce5cc44c909---------------------clap_footer------------------)
[](https://medium.com/m/signin?actionUrl=https%3A%2F%2Fmedium.com%2F_%2Frepost%2Fp%2Fdce5cc44c909&operation=register&redirect=https%3A%2F%2Fmedium.com%2F%40hdhffxfg%2Fbreaking-access-control-logic-manipulation-role-escalation-part-2-dce5cc44c909&user=Yassin+Hamada&userId=0099af262952&source=---header_actions--dce5cc44c909---------------------repost_header------------------)
[](https://medium.com/m/signin?actionUrl=https%3A%2F%2Fmedium.com%2F_%2Fbookmark%2Fp%2Fdce5cc44c909&operation=register&redirect=https%3A%2F%2Fmedium.com%2F%40hdhffxfg%2Fbreaking-access-control-logic-manipulation-role-escalation-part-2-dce5cc44c909&source=---header_actions--dce5cc44c909---------------------bookmark_footer------------------)
[Listen](https://medium.com/m/signin?actionUrl=https%3A%2F%2Fmedium.com%2Fplans%3Fdimension%3Dpost_audio_button%26postId%3Ddce5cc44c909&operation=register&redirect=https%3A%2F%2Fmedium.com%2F%40hdhffxfg%2Fbreaking-access-control-logic-manipulation-role-escalation-part-2-dce5cc44c909&source=---header_actions--dce5cc44c909---------------------post_audio_button------------------)
Share
After exploring path manipulation, we move into the core of web vulnerabilities: **Business Logic Manipulation** and **Role Escalation**. This is where we stop looking at _where_ we are in the application and start looking at _what_ we can make the server do.
## 1. User Role Controlled by Request Parameter
Sometimes, the authorization check isn’t based on the path, but on a hidden parameter sent alongside your data.
* **Methodology:** After
URL Source: https://medium.com/@hdhffxfg/breaking-access-control-logic-manipulation-role-escalation-part-2-dce5cc44c909?source=rss------cybersecurity-5
Published Time: 2026-06-14T21:53:54Z
Markdown Content:
[Sitemap](https://medium.com/sitemap/sitemap.xml)
[Open in app](https://play.google.com/store/apps/details?id=com.medium.reader&referrer=utm_source%3DmobileNavBar&source=post_page---top_nav_layout_nav-----------------------------------------)
Sign up
[Sign in](https://medium.com/m/signin?operation=login&redirect=https%3A%2F%2Fmedium.com%2F%40hdhffxfg%2Fbreaking-access-control-logic-manipulation-role-escalation-part-2-dce5cc44c909&source=post_page---top_nav_layout_nav-----------------------global_nav------------------)
[](https://medium.com/?source=post_page---top_nav_layout_nav-----------------------------------------)
Get app
[Write](https://medium.com/m/signin?operation=register&redirect=https%3A%2F%2Fmedium.com%2Fnew-story&source=---top_nav_layout_nav-----------------------new_post_topnav------------------)
[Search](https://medium.com/search?source=post_page---top_nav_layout_nav-----------------------------------------)
Sign up
[Sign in](https://medium.com/m/signin?operation=login&redirect=https%3A%2F%2Fmedium.com%2F%40hdhffxfg%2Fbreaking-access-control-logic-manipulation-role-escalation-part-2-dce5cc44c909&source=post_page---top_nav_layout_nav-----------------------global_nav------------------)

# Breaking Access Control: Logic Manipulation & Role Escalation (Part 2)
[](https://medium.com/@hdhffxfg?source=post_page---byline--dce5cc44c909---------------------------------------)
[Yassin Hamada](https://medium.com/@hdhffxfg?source=post_page---byline--dce5cc44c909---------------------------------------)
Follow
3 min read
·
Jun 14, 2026
[](https://medium.com/m/signin?actionUrl=https%3A%2F%2Fmedium.com%2F_%2Fvote%2Fp%2Fdce5cc44c909&operation=register&redirect=https%3A%2F%2Fmedium.com%2F%40hdhffxfg%2Fbreaking-access-control-logic-manipulation-role-escalation-part-2-dce5cc44c909&user=Yassin+Hamada&userId=0099af262952&source=---header_actions--dce5cc44c909---------------------clap_footer------------------)
[](https://medium.com/m/signin?actionUrl=https%3A%2F%2Fmedium.com%2F_%2Frepost%2Fp%2Fdce5cc44c909&operation=register&redirect=https%3A%2F%2Fmedium.com%2F%40hdhffxfg%2Fbreaking-access-control-logic-manipulation-role-escalation-part-2-dce5cc44c909&user=Yassin+Hamada&userId=0099af262952&source=---header_actions--dce5cc44c909---------------------repost_header------------------)
[](https://medium.com/m/signin?actionUrl=https%3A%2F%2Fmedium.com%2F_%2Fbookmark%2Fp%2Fdce5cc44c909&operation=register&redirect=https%3A%2F%2Fmedium.com%2F%40hdhffxfg%2Fbreaking-access-control-logic-manipulation-role-escalation-part-2-dce5cc44c909&source=---header_actions--dce5cc44c909---------------------bookmark_footer------------------)
[Listen](https://medium.com/m/signin?actionUrl=https%3A%2F%2Fmedium.com%2Fplans%3Fdimension%3Dpost_audio_button%26postId%3Ddce5cc44c909&operation=register&redirect=https%3A%2F%2Fmedium.com%2F%40hdhffxfg%2Fbreaking-access-control-logic-manipulation-role-escalation-part-2-dce5cc44c909&source=---header_actions--dce5cc44c909---------------------post_audio_button------------------)
Share
After exploring path manipulation, we move into the core of web vulnerabilities: **Business Logic Manipulation** and **Role Escalation**. This is where we stop looking at _where_ we are in the application and start looking at _what_ we can make the server do.
## 1. User Role Controlled by Request Parameter
Sometimes, the authorization check isn’t based on the path, but on a hidden parameter sent alongside your data.
* **Methodology:** After
DeepCamp AI