IDOR is an access-control vulnerability where the application uses user-supplied object identifiers without authorisation checks.
Example: GET /api/invoice/1337 — changing the ID exposes another user's record.
Mitigation
Per-object authorisation checks, use GUIDs instead of sequential IDs.