DigiNews

Tech Watch by Johan Denoyer

← Back to articles

I Could've Rickrolled the FIFA World Cup. All I Needed Was My ID.

Quality: 8/10 Relevance: 9/10

Summary

The FIFA World Cup 2026 revealed a critical client-side authorization flaw in FIFA’s internal platforms that exposed live streams, match data, and admin capabilities to NO_ROLES accounts. The author documents the discovery, the exposure chain, the response timeline, and a follow-up fix, emphasizing server-side enforcement, responsible disclosure, and IAM best practices.

🚀 Service construit par Johan Denoyer