Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-58 — Restful Privilege Elevation
CAPEC-58

Restful Privilege Elevation

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: High. An adversary identifies a Rest HTTP (Get, Put, Delete) style permission method allowing them to perform various malicious actions upon server data due to lack of access control mechanisms implemented within the application service accepting HTTP messages.

Mitigation

Design: Enforce principle of least privilege | Implementation: Ensure that HTTP Get methods only retrieve state and do not alter state on the server side | Implementation: Ensure that HTTP methods have proper ACLs based on what the functionality they expose

Details

Platforms
Software
Hardware
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.