OWASP_API_TOP10API6:2023voice-validated

OWASP_API_TOP10 API06: API6:2023

OWASP_API_TOP10

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-06-20

Regulation text

APIs vulnerable to this risk expose a business flow — such as buying a ticket, posting a comment — without compensating for how the functionality could harm the business if used excessively in an automated manner. Includes lack of rate-limiting, lack of CAPTCHA, no anti-automation on critical workflows.

ATT&CK techniques this article tests · 15

TechniqueWhy it mapsConfidence
T11901. Attackers exploit public-facing API endpoints lacking rate-limiting to conduct reconnaissance or gain initial access.
90%
T10782. Brute-forcing credentials via an API without rate limits enables attackers to acquire valid accounts.
80%
T10593. Automated scripts interact with APIs to execute business logic excessively, causing resource strain.
60%
T11364. Unlimited account creation via API endpoints facilitates persistent access and resource abuse.
90%
T10685. Excessive API calls can trigger race conditions or logic bypasses, leading to privilege escalation.
70%
T15626. High volume API requests overwhelm monitoring and logging systems, impairing defensive capabilities.
80%
T11107. Lack of rate-limiting on authentication endpoints directly permits unlimited credential guessing.
100%
T10468. Automated scanning of API endpoints discovers available business flows for exploitation.
70%
T10879. Automated enumeration of user accounts via unrestricted API access reveals valid targets.
80%
T100510. Excessive API calls retrieve large volumes of sensitive data from backend systems.
70%
T107411. Automated collection of data through API calls stages information for subsequent exfiltration.
60%
T107112. Attackers use standard API protocols for command and control, leveraging unrestricted access.
70%
T156713. Unrestricted API access enables automated exfiltration of sensitive data over web services.
90%
T149814. Excessive requests to an API cause service unavailability, resulting in Denial of Service.
100%
T149915. Targeting specific API endpoints with high request volumes leads to Endpoint Denial of Service.
100%

Defending mitigations · 6

MitigationWhat it doesConfidence
M10351. Implementing rate-limiting and throttling on API endpoints prevents excessive use of business flows.
100%
M10472. Regular auditing of API access logs identifies anomalous usage patterns and potential abuse.
90%
M10383. Strong user account management, including CAPTCHA, prevents automated account creation and brute force.
80%
M10404. Network Intrusion Prevention Systems detect and block malicious automated API traffic.
90%
M10515. Filtering network traffic based on request patterns, IP, or user-agent blocks automated attacks.
90%
M10206. Automated systems detect and respond to excessive API usage, protecting critical business flows.
90%

Underlying weaknesses · 7

CWEWhy it persistsConfidence
CWE-7701. The API allocates resources without limits or throttling, enabling excessive consumption.
100%
CWE-4002. Uncontrolled resource consumption occurs when an API allows unlimited requests, leading to system degradation.
90%
CWE-3073. Improper restriction of excessive authentication attempts allows brute-force attacks against API login endpoints.
100%
CWE-8624. Missing authorization permits any user to access and excessively use sensitive business flows.
80%
CWE-2875. Improper authentication, such as lacking CAPTCHA, allows automated access to API functions.
70%
CWE-206. Improper input validation can exacerbate the impact of excessive requests on API business logic.
60%
CWE-6037. Reliance on client-side anti-automation mechanisms for APIs allows easy bypass by attackers.
50%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0161 compute · voice-rubric self-validated