An API authentication logs show user Alice (tenant_id=5) successfully authenticated with a valid JWT and accessed /api/documents/8471. The database shows document 8471 belongs to tenant_id=12. The API returned HTTP 200 with the document content. Which vulnerability is MOST likely present and what is the primary control failure?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- ASession fixation forces a victim to use a session ID the attacker chose; here Alice used her own valid token, and the failure is what she was allowed to read.
- BAlgorithm confusion would mean a forged or tampered token, but the log shows a valid JWT for Alice, so signature checks are not where the control failed.
- CCredential stuffing reuses leaked passwords; the log shows genuine authentication with a valid JWT, so this is an authorization problem, not a login one.
- DCorrect: the API checked who Alice was but not whether document 8471 belonged to her tenant, which is Broken Object Level Authorization, first in the OWASP API Top 10 2023.