
Broken Function Level Authorization Vulnerability in OopsSec Live Stream
ctfbroken_access_controlauthorizationapi_securitylive_stream_hijackweb_security
Challenge 7/36 focuses on Broken Access Control, specifically Broken Function Level Authorization (live stream hijack). This vulnerability is categorized as Medium in severity and relates to Authorization, with an estimated completion time of 45–60 minutes. OopsSec Live hides broadcast controls from non-admins in the user interface, but the API fails to verify user roles, allowing any logged-in customer to replace the live stream. This mirrors the 2026 FIFA internal-systems hack. To participate, users can spin up the lab using the command 'npx create-oss-store my-ctf-lab'. Additional resources include the challenge roadmap, a walkthrough with spoilers, and the GitHub repository for OopsSec Store.