Slide 11 of 28
Part 2 · How It WorksSlide 11
Slide 11 · Horizontal BOLA — Real Example
Peloton. 4 million users. No authentication required.
This is horizontal BOLA at scale.
Real Incident · May 2021
Peloton API — Unauthenticated User Data Exposure

Security researcher Jan Masters discovered that Peloton's API endpoint /api/user/{userId}/workout_list returned private user data with no authentication required at all — not even a valid login.

By simply changing the userId in the URL, anyone could retrieve any Peloton user's: age, gender, city, weight, workout history, and fitness statistics.

Masters reported the vulnerability to Peloton in January 2021. Peloton acknowledged it — then took three months to fix it, only after TechCrunch published the story.

What made it horizontal: Every account was the same type — regular Peloton user. There was no privilege difference. You just accessed another user at the same level by changing their ID.
The human cost

Weight. Fitness level. City. Workout habits. For 4 million people. Someone's health data is deeply personal. It can affect their insurance, their employment, their relationships. They had no idea it was sitting in the open.

What Peloton got wrong

Two failures layered on top of each other: no authentication check at all, and no object-level authorization. The endpoint was wide open. Any HTTP request with a userId returned data. No token, no session, nothing.

← Back Now show me vertical BOLA →