Approval bypass

Context#

Approval bypass targets transitions that require a second principal (manager sign-off, risk review). Typical failures include self-approval (same user as requester and approver), reused approval tokens, weak binding of approval identifiers to the request payload, and routes such as POST /approve that omit role or organization checks.

Theory#

Map states (for example pending → approved → settled) and which credential may fire each transition. Overlap with Access control when the failure is a missing role on a route; this page emphasizes workflow graphs that include an explicit approver transition.

Practice#

Self-approval attempt#

  • Create a request as user A, then call the approve endpoint authenticated as A when the product claims segregation of duties.

Replay stale approval id#

  • Capture approvalId from a completed flow, start a new request, and substitute the old approvalId if the server accepts it without binding to a new payload hash.

Tools#

  • Burp Suite
  • curl

Cookie Consent

We use cookies to enhance your experience. Learn more