ended6월 18일· 1 sources

내 ID만 있으면 FIFA 월드컵 전체에 Rickroll을 틀 수 있었다

Why it matters

A critical authorization flaw in FIFA's World Cup 2026 infrastructure allowed any registered user to access live streaming controls and match data because role verification was implemented only on the client side while the backend API enforced no permissions. This vulnerability exemplifies a widespread enterprise security misconception that frontend validation provides sufficient access control. The incident underscores the necessity of server-side authorization enforcement as the primary security layer and highlights how responsible disclosure practices can identify critical flaws before malicious exploitation.

1
Sources
+0
24h
Growth
76d
Active
Authorization bypassJWT validationStreaming infrastructureClient-side securitySecurity disclosure

Sources

Related Issues