This case study documents the discovery, responsible disclosure, and successful remediation of a
Broken Access Control vulnerability in a live government API handling citizen complaint records.
The flaw allowed any unauthenticated actor to issue bulk HTTP GET requests against the
/api/v1/complaints collection endpoint and receive structured PII for over 1,000+ citizen entries
including full names, phone numbers, and sensitive allegation descriptions.
The root cause was a Default Allow posture inherited from the public submission flow β
the API correctly permitted anonymous POST requests for citizen submissions but failed to restrict
GET access at the method level, exposing the entire complaints collection to unauthenticated reads.
Responsibly disclosed to MOI IT stakeholders. Patch verified February 19, 2026.
| Field | Detail |
|---|---|
| System | Government Complaint Support System (CSS) |
| API Stack | Spring Boot, Spring Security |
| Endpoint | /api/v1/complaints |
| Method | HTTP GET (unauthenticated) |
| Data Exposed | Citizen PII β names, phone numbers, complaint descriptions |
| Records Exposed | 1,000+ entries |
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β CSS API ACCESS CONTROL FLAW β
β β
β [Citizen] ββPOSTβββΆ /api/v1/complaints β
permitAll() β
β β β
β [Attacker] ββGETββββΆ /api/v1/complaints β no restriction β
β β β
β βΌ β
β Full JSON dump of 1,000+ PII records β
β { name, phone, description, status } β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Deployed Bubble-Scanner to map the Spring Boot
API surface. The tool's Bubble-Dive Engine recursively fuzzes endpoints and triggers
sub-scanners on every 200 OK response, including:
- Source code scavenging (regex patterns for leaked API keys, tokens, hardcoded credentials)
- RCE vector identification (file upload forms, unvalidated input fields)
- Basic error-based SQLi probing on discovered parameters
bubble_dive() {
head -n 1000 "$WORDLIST" | while read -r path; do
url="${base_url%/}/${path}"
res=$(curl -s -o /dev/null -w "%{http_code}" "$url")
if [ "$res" == "200" ]; then
scan_source_code "$url" # hunt for leaked secrets
check_upload_vuln "$url" # identify RCE vectors
fi
done
}Observed a discrepancy between the authenticated admin dashboard (correctly access-controlled) and the raw API routes beneath it. The frontend enforced auth; the backend did not.
Unauthenticated GET to the complaints collection returned a full database dump instead of
the expected 403 Forbidden:
# Unauthenticated collection probe (pre-patch)
curl -i -k 'https://[TARGET_REDACTED]/api/v1/complaints'Response (anonymized sample):
[
{
"id": 7,
"plaintiffName": "α α»α [REDACTED]",
"phoneNumber": "086******",
"description": "Sensitive allegation description...",
"status": "PENDING"
}
]Delivered a Root Cause Analysis to MOI IT stakeholders identifying the missing method-level security configuration. The recommended fix:
// Spring Security fix (conceptual β applied by MOI IT team)
.requestMatchers(HttpMethod.POST, "/api/v1/complaints").permitAll() // public submissions
.requestMatchers(HttpMethod.GET, "/api/v1/complaints").hasRole("ADMIN") // restrict readsRegression tested all previously successful extraction vectors on February 19, 2026.
All endpoints returned HTTP 403 Forbidden for unauthenticated GET requests.
Public POST submission flow remained functional.
| CWE | Description |
|---|---|
| CWE-284 | Improper Access Control |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor |
| CWE-285 | Improper Authorization (method-level GET/POST distinction missing) |
Score: 7.5 (High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
| Metric | Value | Rationale |
|---|---|---|
| Attack Vector | Network | Exploitable remotely over HTTP |
| Attack Complexity | Low | Single unauthenticated GET request |
| Privileges Required | None | No auth token needed |
| User Interaction | None | Fully automated extraction possible |
| Confidentiality | High | Full PII collection exposed |
| Integrity | None | Read-only β no write access demonstrated |
| Availability | None | No service disruption |
| Metric | Result |
|---|---|
| Discovery date | February 2026 |
| Report submitted | February 18, 2026 |
| Patch verified | February 19, 2026 |
| Time to remediation | < 24 hours |
| Disclosure type | Responsible β coordinated with MOI IT |
| PII records secured | 1,000+ entries |
| Tool | Purpose |
|---|---|
| Bubble-Scanner | Endpoint discovery, source recon, SQLi probing |
| curl | Manual endpoint probing & verification |
| Spring Security docs | Remediation guidance |
Disclaimer: This research was conducted for educational and security-hardening purposes. No data was retained or exfiltrated. All findings were reported directly to the system owner prior to publication.
β οΈ Disclaimer. This document is a sanitised portfolio artefact produced from an authorised penetration test. All identifying data has been redacted or replaced with documentation-reserved placeholders. It contains no client data, no live targets and no novel exploit code. Techniques shown are standard, publicly documented, and provided for educational and defensive purposes only. Do not test any system you do not own or lack explicit written authorisation to assess.