Skip to main content

Siemba API Security Testing

Siemba Automates IDOR Testing Across Full API Collections

Image
Siemba Automates IDOR Testing Across Full API Collections

Atlanta – September 20, 2026 -- Siemba has launched automated testing for insecure direct object reference (IDOR) flaws, cutting the time to scan a 200-endpoint API collection to under an hour, a task the company says has typically taken human testers days or weeks.

IDOR ranks first among OWASP's API Security Top 10 risks

IDOR, classified by OWASP as broken object level authorization, occurs when an endpoint fails to verify that a caller-supplied identifier belongs to them, allowing a single changed number in a request to expose another user's data. Siemba's Chief Security Officer Sandhya Prashanth said the flaw "drives a huge share of real-world breaches" and requires little more than systematic testing across every endpoint to detect.