Siemba Adds Automated Testing for API Access Flaws
The feature checks live APIs for authorization weaknesses that could let users view or change another person’s data.
- By Chelsey Arries
- Sep 23, 2026
Siemba has added automated insecure direct object reference (IDOR) checks to its API Security Testing capability.
The feature targets authorization flaws that can allow users to access or modify someone else’s data by changing an identifier in a request. It is available through the company’s platform, which tests application programming interfaces using REST, GraphQL and SOAP.
Testing begins with a customer’s API definition or collection and supplied identifiers. Siemba said the system generates tests for endpoints containing identifier parameters, examines API responses and provides steps for reproducing confirmed findings. Source code is not required.
This automation allows human penetration testers to handle more complex assessments, including chained attack paths and nuanced privilege boundaries.
About the Author
Chelsey Arries is assistant editor of Security Today, Campus Security Today, Occupational Health & Safety and Environmental Protection Online.