Accounting For Impact of Coronavirus Disease of 2019

Scrubbed

Scrubbed

Accounting For Impact of Coronavirus Disease of 2019
Understanding the direct and indirect effect of COVID-19 can prepare the company’s operations, future plans, and key information communicated to stakeholders.

The Coronavirus Disease of 2019, or COVID-19, is an evolving concern that has dealt a huge blow in the Global Financial Market and industries in general, disrupting value chains and daily living of the world’s population. Originally declared as a public health emergency on January 30 by the World Health Organization, the phenomenon is now considered as a Pandemic, and full impact remains evolving. As it affects and creates a toll on human activity and quality of living in general, COVID-19 poses great uncertainty to other facets of businesses. Directly, we have seen the effects in the companies’ supply chains as it halts workforce, production of goods and rendering of services, and forces governments to regulate economic activities. Further, we have identified selected indirect effect on the companies’ financial statements that may pose significant effects in the long run.

FASTalks is here to affix your senses on things that matter to your stakeholders, and ensure that your accounting teams—the Scrubbed team— cover considerations that stakeholders might ask—because in times of crisis, stability and knowing the impact of uncertainties matter.

In a Nutshell

  • COVID-19 poses 2019 financial statement modifications on Going Concern (ASC 205-40) and Subsequent Events (ASC 855)
  • COVID-19 affects Revenue Recognition for Q1’2020 onwards (ASC 606 and 326)
  • COVID-19 presents accounting for unusual expenses for Q1’2020 onwards (ASC 220 and 225)
  • COVID-19 opens uncertainties towards impairment of certain assets (ASC 350 and 360)
  • COVID-19 affects Lease accounting for Q1’2020 onwards (ASC 84
  • COVID-19 required regulatory reforms by providing tax filing reliefs for State (CA) and Federal Tax Returns


2019 FINANCIAL STATEMENTS IMPACT

Consistent with ASC 855 provisions, companies should evaluate whether events occurring subsequent to the Balance Sheet date (12/31/2019) require disclosure or adjustments in the financial statement.

Managements’ action point is to consider the adjustment in the financial statement, via notes, or via adjusting financial amounts.

  • Non-Adjusting Events / Nonrecognized Subsequent Events. For 12/31/2019 filings, financial reporting impacts will be limited to disclosures in the notes to financial statements. Examples include closure of facilities, change in debt arrangements or restructuring, change in business practices (such as movement to online channels), and modifications in covenants.
  • Adjusting Events / Recognized Subsequent Events. Consistent with current practice, if the event is a culmination of an already existing event as of Balance Sheet date, example of which is the US-China trade restriction, then the financial impact of the event constitutes adjustment in the financial statement details as of 12/31/2019.

Significantly, for those not yet issuing the financial statements for 12/31/2019, a grave consideration is the factor of the identified uncertainty (COVID-19). Consistent with the provisions of ASC 205 Subtopic 40, a reporting entity’s exposure to coronavirus-affected areas may raise or contribute to other existing facts and circumstances that collectively raise substantial doubt about the entity’s ability to continue as a going concern.

Managements’ action point is to reassess the following:
  • Assess whether liquidation accounting is applicable (COVID-19 may have disrupted an entire industry, and lack of revenue-generating activities may affect the viability of the business);
  • Consider whether impact of COVID-19 is material to the company’s ability to continue as a going concern (did it significantly alter the business model of the company?);
  • Consider Managements’ plans to mitigate the adverse conditions or events;
  • Consider effective implementation of managements’ plans and viability of resolving the substantial doubt as to the impact in the company’s operations.

Currently, 42% of SEC Issuers have included COVID-19 as incremental business risk and considered the factor in the companies’ abilities to continue as going concern. If positive outcome is expected based on the action points above, then a mere disclosure is required, considering that COVID-19 impacts the operations of the company materially.

CONSIDERING REVENUE RECOGNITION CONSTRAINTS OF COVID-19

Consistent with ASC 606 provisions, three factors affecting revenue recognition and subsequent collection must be taken into consideration when recognizing revenue for Q1’2020 onwards.
  • Adjustment of Variable Considerations. Variable consideration is estimated at contract inception and needs to be reassessed at each reporting date. But variable consideration can only be recognized to the extent it is probable a significant reversal will not occur when the uncertainty is resolved. ASC 606 describes examples such as volume discounts, rebates, returns, refunds, and royalties, liquidating damages. Consideration is also variable if it is contingent on a future event and its occurrence, such as meeting performance goals or deadlines, or a customer achieving a certain outcome, such as a distributor meeting a target level of gross margin upon resale. 

    Given the disruption in the supply chain, management is enjoined to consider the following: (a) adjust the rates of returns and refunds with some kind of forward-looking factor, as opposed to historically analyzing rates. In this view, retrospective analysis may need to be adjusted; (b) consider the probability of performance goals or deadlines not being met due to adverse effects in the economy.
  • Assessment of Collectability of Contracts at Day 0. Salient provision of ASC 606 is to ensure that contracts must meet the collectability threshold—being probable. US GAAP defined “probable” as “likely to occur,” which is generally considered at 75% to 80% threshold. While it is a standard procedure to assess the bad-debts on occurring sales, it is a great concern as to whether the credit quality of the customers have been impaired at the onset of the sale/rendering of service.

    We opt to remind Management that revenue can only be recognized when collection of consideration is probable at the perfection of the contract/delivery of goods. This criteria must be met, and Management is encouraged to assess customers who are credit-impaired on Q1’2020, in order to address existence issues of revenues.
  • Impairment of Receivables amidst COVID-19. While incurred losses model generally apply for private companies, it is important to note that ASC 326, guidance on current expected credit loss model (CECL), suggests that a forward-looking adjustment be considered in the computation of impairment of receivables. 

    We encourage management to consider a forward-looking adjustment (e.g. adjustment of rates such as increase in expected impairment rate) related to overall credit deterioration of customers. Historical analysis (net flow rates) and previous credit profiling may not be applicable in the face of the pandemic, and we are encouraged to adjust our models accordingly.

 

ACCOUNTING FOR UNUSUAL EXPENSES RELATED TO COVID-19

Unexpected costs are likely to be incurred because of COVID-19. In recognizing these expenses, ASC 220 and ASC 225 provide guidance on what items are considered “unusual” and “infrequent.”

“Unusual” events are those with high degree of abnormality that is clearly unrelated, or incidentally related to the ordinary activities of the business in its operating environment. On the other hand, “infrequent” events are those that are not reasonably expected to be incurred again in the future, within the operating environment.

The standard also classifies the operating environment to consider the characteristics of the industry, the geographical location and the governmental regulation. For example, an entity handling national disasters, may consider expenses from response for emergencies as part of their normal operations, and would not be classified as “unusual” or “infrequent”.

Examples of which are, but not limited to, the following:
  • Planning, preparation, and prevention activities for Management’s response to COVID-19
  • Cancellation of events and delays in the production costs
  • HR Expenses (additional security and staffing)
  • Increase in IT related expenses due to additional access management tools/remote work set-up

Management’s action point is to provide separate consideration in accounting for these expenses.
When incurring unusual and infrequent expenses, generally, these expenses are presented as part of the statement of comprehensive income with supporting disclosure. A detailed list of the accounting treatment for these items are summarized below in accordance with ASC 220:
  • Presentation as a separate component of income from continuing operations, (not presented net of tax);
  • Presentation as a separate component of the financial effect of unusual and infrequent events;
  • Disclosure of unusual and infrequent expenses, including nature and circumstance; and
  • Recognition of receivable/gain from insurance policies to the extent that the amount of losses has been recognized in the financial statements (ASC 450)


Our consensus with management disclosure and analysis is this: in order not to disrupt the performance measurement of some industries, these expenses should be considered outliers, and there should be a separation in the evaluation and management of key performance indicators (especially in the healthcare industry).

PROBABLE IMPAIRMENT OF ASSETS

Respective companies’ financial performance and future projections as to the health and wealth of the business may be significantly affected, either on the demand side or the supply side. Factors include:
  • Demand Side. A significant demand for certain industries have become affected negatively, such as airlines, hotel and hospitality, travel, and large-scale event-based industries. Since uncertainty played a significant role, revenue generation and possible cash inflow may be negatively affected. Management needs to adjust revenues conservatively to check value in use.
  • Supply Side. If supply chain is based on geographical locations widely affected by lockdowns or severe inability to mobilize workforce due to the health toll of the disease, and constraints in the supply meant inability to cater to demand, then Management needs to adjust revenues limited only to the expected supply.
  • Other factors. Other factors needing to be considered for triggering events include presence and availability of alternative workforce and other regulatory restrictions.

The guidance for goodwill and intangibles requires that an impairment test be performed when a triggering event occurs. In this case, the triggering event is the volatile and negative impact of the event in the Stock Markets—and normal litmus test is to check whether market capitalization falls below carrying value of the assets.

If a thorough analysis is conducted, companies should assess whether a triggering event has occurred, and if so, management should follow the applicable guidance. Normally, this includes Step 0—qualitative assessment of factors, then Step 1—quantitative assessment. The company should consider how assumptions in its financial projections may be impacted by decreased demand for its products or services or extended disruptions to its supply chain, manufacturing operations, or global workforce.

Other considerations for Asset Impairment include:

  • Similarly, triggering events discussed above relates to tangible assets as well. Idle property and equipment may present factors of impairment through lack of utility.
  • In inventories, write-down of value due to Net Realizable Value (NRV) decline may be expected. Excess inventory for goods without demand must be carefully analyzed. Other excess inventory that will not be realized within the normal operating cycle may be classified as “long-term” assets.
  • Idle production capacity, and depreciation of idle assets in the event of production restriction due to lockdown, may be charged outright to cost of goods sold rather than capitalizing to inventories.
  • For equity instruments, investment in companies situated in hardly-hit areas needed to be assessed as to whether “other than temporary impairment” factors exist.

COVID-19’S IMPACT ON LEASE accounting

Certain impact of COVID-19 in lease accounting needs to be considered operationally and financially. They are as follows:

  • Impairment. On lessee scale, one or more of the aforementioned economic and financial markets effects may trigger a requirement for the lessee to assess one or more of its asset groups that includes an ROU asset for impairment under ASC 360 (property, plant and equipment). For example, the economic effects of the COVID-19 outbreak may result in a ‘significant adverse change in the business climate that could affect the value of the long-lived asset. 

    Lessors may find that some of their underlying assets held for lease are impaired if lessee demand for those assets significantly decreases or rental rates decline precipitously.
  • Abandonment. A company may commit to abandon an ROU asset if it concludes it can no longer make use of it as a result of the COVID-19 outbreak, and either cannot or will not sublease it. For example, a company that is leasing overflow fulfillment center space may determine that space is no longer needed because sales have, or are expected to, decline significantly.
  • Lessee discount rates. A lessee’s incremental borrowing rate, typically used by lessees as the ‘discount rate for the lease’, may be affected if interest rates significantly change (e.g. due to central bank monetary stimulus) or its borrowing costs otherwise change (e.g. because its credit rating declines).
  • Lessee reassessments. One or more actions a lessee takes in response to the effects of the COVID-19 outbreak may trigger a requirement to reassess the term of, or an option to purchase the underlying asset in, one or more leases.
  • Fair values. Multiple aspects of ASC 842 lease accounting depend on fair value (e.g. of underlying assets and ROU assets). The fair value of an ROU asset affects whether and how much impairment is recognized on an ROU asset. Fair values may be affected by significant economic events such as the COVID-19 outbreak.
  • Collectability. Collectability of lease payments at inception of contract, and subsequent collection thereof is governed by the effects of COVID-19 as discussed in the previous pages (ASC 606 and ASC 326).

WE’D LOVE TO EXPAND OUR SERVICES.

To ensure that all factors are considered in the pursuit of relevant and fair financial reporting, our outsourced accounting team services like SaaS accounting expertise can be scaled to accommodate your business needs, especially in considering accounting and reporting impact of COVID-19. Our Technical accounting Group supports the accounting services and provides a thorough analysis of factors outside the normal course of business.

E-mail us at [email protected] for full consultancy assessment.

Disclaimer

The information contained herein is of a general nature and is not intended to address the circumstances of any particular individual or entity. It is not intended to be relied upon as accounting, tax, or other professional service. Please refer to your advisors for specific advice. Although we endeavor to provide accurate and timely information, there can be no guarantee that such information is accurate as of the date it is received or that it will continue to be accurate in the future. No one should act upon such information without appropriate professional advice after a thorough examination of the particular situation.

How Scrubbed can help?

Companies may find it challenging to adopt and transition to the upcoming reporting requirements that meet regulatory and stakeholder demands. To assist companies in complying with the current and developing requirements, the Scrubbed ESG team stays informed on standard-setting developments and regulations. Our ESG Team can help you.

Contact Scrubbed to assist you in this transition to a sustainable business.

CONTACT US
How Scrubbed can help?

Related Content

Blogs

Redefining the Accounting Workforce: Finding the Right Talent Model for Your Firm

Redefining the Accounting Workforce: Finding the Right Talent Model for Your Firm

The accounting profession is currently going through major changes. With talent shortages, shifting client expectations, and growing competition, CPA firms are pressured to rethink how they build and manage their teams.In a recent webinar hosted by Dan Hood, the Editor-in-Chief at Accounting Today, industry experts Rizza De Guzman, the Lead Director for Firm Client Services at Scrubbed, and Jack Reagan, Partner at UHY Advisors, explored the recent shift in the industry and shared their thoughts on how firms can adjust to these challenges. They offered their expertise and strategies to help firms stay competitive and move forward with confidence.Why Firms Are Struggling With the Current Staffing ModelOne of the biggest challenges accounting firms face today is the growing gap between the demand for skilled professionals and the number of people available to do the work.Rizza highlighted several factors that could be causing this shortage, such as the retirement of experienced professionals, the lack of new professionals entering the field, and other industries attracting potential talent with competitive pay and more appealing career paths. As a result, many firms are finding their teams stretched thin. They’ve done all they can with the staff they have, and it’s becoming clear that relying solely on traditional hiring methods isn’t sustainable.Another challenge that Jack mentioned is how client needs have evolved. Work that used to be predictable and ongoing is now more project-based and specialized. So, the skills that you may need now might be different from the skills you need tomorrow. This unpredictability means that firms need to be able to quickly scale their teams up or down, and that kind of agility is hard to achieve with the current staffing model. For Jack, “having that flexibility to match not only the cycle but then the skill set that the project demands is critical.”Building Flexible Teams Through Hybrid and Outsourced StaffingOnce the challenges around talent became clear, the conversation shifted to what firms can do about it. One of the key solutions Rizza discussed was to explore other models, like outsourcing, to create a more agile and scalable workforce. She defines outsourcing as a situation when a company ”fully or partially delegates work to an external partner who becomes an extension of your team.”This kind of model helps firms stay agile and allows them to tap into specialized skills when needed, manage costs more effectively, and adjust quickly as workloads shift. Instead of trying to overload internal teams with work or hire full-time staff for short-term needs, firms can bring in the right expertise at the right time.How to Make Outsourcing Work for Your FirmOne of the most effective ways for firms to stay competitive is by bringing in outside expertise. But making that work takes more than just hiring a third party and hoping for the best. Successful outsourcing starts with clearly defined roles and expectations. Open communication is key, and the relationship needs ongoing attention, not just a one-time setup. Regular check-ins and performance reviews help keep everything on track.Rizza highlights that one of the first steps for companies to start exploring outsourcing or hybrid workforces is by taking a good look at where their team stands today. What skills are missing? What kind of work is piling up? From there, firms can start small. Try a hybrid model, see what works, and adjust as you go.Jack agreed, but noted that for these partnerships to work, firms need to treat outsourced professionals like true team members. According to him, it’s important that firms “…have a say on who is gonna be part of the team,” rather than just being assigned an employee, as this helps set the culture in the workplace.And while working remotely is nothing new, as necessitated by the recent pandemic, trust is another big piece of the puzzle. Beyond scheduled meetings, informal chats and the occasional in-person visit can go a long way in strengthening the connection between the firm and its external team and making the collaboration more effective.One example of this is leveraging fractional CFO services, which allows firms to access high-level financial expertise without the commitment of a full-time hire.Remember, there’s no single formula for success here. Every firm is different. The best approach is one that reflects your client’s needs, internal strengths, and long-term goals.Take Action TodayOne thing became clear throughout the discussion: doing nothing is not an option. For Rizza and Jack, the long-term sustainability, growth, and agility offered by outsourcing talent is the way to go.Competitors are already changing how they staff their teams, and firms that don’t adapt risk falling behind, both in terms of competitiveness and their ability to attract and retain top talent. It’s time for firms to rethink their workforce strategy, focusing on flexibility, building strong partnerships, and using technology along with specialized SaaS accounting expertise to their advantage.How can firms maintain quality control when outsourcing talent?This comes down to choosing the right partner from the start. Be sure to take the time to check their credentials and look into businesses that really understand the industry. Don’t be afraid to ask for references to make sure you find the right fit. Once you’re already working together, regular check-ins and clear communication go a long way in making sure everything stays up to your expectations.Can outsourcing help with seasonal workload spikes?One of the biggest advantages of outsourcing is the flexibility to scale up or scale down depending on your business needs. In fact, a lot of firms may bring in outsourced talent during peak times to help manage the extra workload and avoid overwhelming the internal team.Are outsourcing and hybrid models the same?While outsourcing and hybrid work environments both involve remote work, they are fundamentally different work models. Outsourcing involves bringing in external talent into the team while a hybrid set up has more to do with the location of the internal team. Hybrid can also include external talent, making it a mix of both internal and external resources.How can smaller firms start integrating an outsourced team without overextending the budget?The best thing to do is to start small; you don’t have to hire several people at once. Consider outsourcing time-consuming tasks first, like bookkeeping, to determine whether this staffing model works well for your organization. Over time, you can scale based on performance and necessity.How do I choose the right outsourced accounting provider for my biotech company?Start by identifying your company's accounting needs, such as bookkeeping, financial reporting, ASC 606 compliance, or managing R&D tax credits. Then, evaluate your potential providers based on how much experience they have in the biotech industry and with the unique challenges and regulatory requirements your business faces. Review client testimonials and references from similar biotech companies to get a sense of their track record and expertise. Finally, confirm that their services are scalable to support your business as it grows, and that budgets and service levels are in line with your goals.Connect With ExpertsThe landscape for CPA firms is shifting quickly; with fewer professionals entering the field and client needs becoming more complex, the traditional staffing model is becoming harder to sustain. Firms need more flexibility and access to high-level talent without overloading their internal teams.However, finding the right fit in a sea of talent can be difficult and overwhelming. That’s where Scrubbed comes in. We partner with CPA firms and provide outsourced accounting, finance, and audit services to help clients scale their organization smarter and more efficiently. Ready to explore alternative staffing solutions? Schedule a consultation with our team today and discover how smart outsourced accounting team can benefit you.If you missed the webinar, you can watch it here.

Read More >
Blogs

Demystifying Financial Planning for SaaS Companies

Demystifying Financial Planning for SaaS Companies

At Scrubbed, we have extensive experience helping SaaS businesses achieve financial success. We’ve combined our knowledge and best practices into a clear and actionable 6-part series designed to maximize your profitability.This third installment focuses on financial forecasting and planning strategies tailored to SaaS businesses.Looking for Expert Accounting And Finance Support For Your SaaS Business? Click here!In the dynamic SaaS world, recurring revenue fuels growth, and accurate financial forecasting and planning are vital for steering your venture toward success. Your financial model serves as your compass, guiding you with clear insights into the financial impact of every choice but staring down a blank spreadsheet can feel daunting, so we’ve gathered some best practices to help you craft a model that will support your growth goals.1. Build Your Financial ModelFinancial models are the bedrock of informed decision-making in any business. They provide invaluable insights into the financial impact of your every move, allowing you to move strategically towards growth and profitability. Some of the areas where they provide valuable insight are:Pricing strategies: Models let you test different pricing options and pinpoint the sweet spot between maximizing revenue and attracting customers. You can consider factors like costs, volume, and customer segments to tailor pricing strategies for different user groups.Hiring decisions: By forecasting future needs and analyzing costs versus benefits, models help you build the optimal team size and skillset. This ensures you have the right workforce in place to support your growth plans without overspending.Investment opportunities: Models equip you to assess the financial viability of potential investments, allowing you to prioritize projects, manage risk, and allocate resources strategically. This ensures you invest in opportunities with the highest potential return, maximizing your impact with limited resources.In essence, your financial model is your decision-making compass. It provides direction and clarity, guiding you toward success by revealing the financial implications of your choices. It needs to include:Revenue forecast: The revenue forecast identifies and predicts various income streams, including subscription fees, initial setup charges, usage-based billing, and additional services. It allows you to consider key factors like diverse pricing tiers, anticipated customer acquisition, and potential churn rates. Analyzing historical revenue data is a fundamental approach to revenue forecasting for SaaS businesses. The analysis examines past trends, growth rates, seasonality patterns, and other historical metrics to identify patterns and extrapolate future performance. While historical data is your foundation, you should also integrate market analysis, growth plans, and competitor insights to paint a more complete picture.a. Expense projections: SaaS businesses have unique cost structures, and you need to factor in some specific operating expenses:b. Personnel costs, including development, sales and management teams, and customer support based on hiring plans and salary trends.c. Marketing expenses should be linked to your acquisition strategy and target audience, including paid advertising, content marketing, and affiliate programs.d. Research and development expenses, including salaries and benefits, development tools and software, and prototyping and user research.Technology costs include cloud hosting, data storage, and security tools that are your virtual backbone.Cash flow projections: Cash inflows and outflows should be forecast over a specific period, considering factors such as operating expenses, capital expenditures, and financing activities. Cash flow projections help assess liquidity, financing needs, and overall financial health.Financial goals and metrics: Track and monitor key metrics such as Monthly Recurring Revenue (MRR), Annual Recurring Revenue (ARR), Average Revenue Per User (ARPU), Customer Acquisition Cost (CAC) to Lifetime Value (CLTV) ratio, and Churn Rate. KPIs provide insights into business performance and inform your strategic decision-making.Don’t expect a clear, unchanging path. Regularly revisit and update your financial plan based on your actual performance and market changes. Think of it as a living document, not a rigid script.While many components of a SaaS financial model are similar to models for other types of businesses, there are some key differences. SaaS financial models typically focus on recurring revenue streams, subscription-based pricing models, customer retention, and scalability. Additionally, metrics such as MRR, ARR, CLTV, and churn rate are unique to the SaaS business model and play a significant role in financial planning and analysis.2. Stress-Test your ModelIt’s important to prepare for different scenarios to be ready to weather or take advantage of changes in the market or your customer base.Start by identifying the factors that significantly impact your financial health, such as pricing changes, churn rates, market growth, or competitor actions. Then, simulate various scenarios in your model to see how these key drivers affect your revenue and expenses. This will highlight potential risks and opportunities you might have missed.Use data visualization to clearly and concisely present your sensitivity analysis findings to stakeholders, including charts and graphs to make complex data easily digestible.3. Use Financial Planning to Inform Strategic Decision-MakingYour model should be a trusted advisor, guiding decisions on product development, pricing strategies, expansion plans, and resource allocation. Use it to test different options and find the one that maximizes your return on investment.However, don’t fall into the trap of over-reliance. Be aware of your financial plan’s limitations and biases, and regularly update it with new data and market insights.As the SaaS landscape evolves, so should your model. Regularly review and update your assumptions, projections, and drivers to ensure the model reflects your changing business environment.Tips to Improve Your Financial Planning:While it can sound daunting, strategic financial planning can increase your company’s sustainability, helping you make better decisions and improve your financial health. If you’re just starting out (or you’re looking to get more out of your financial planning), following these steps can help:Start simply and scale gradually. Don’t get bogged down in complexity.Collaborate with your team. Sales, marketing, and operations input create a comprehensive and realistic model.Embrace iteration. Your model is never truly finished. Continuously refine it based on new data and learnings.Stay ahead of the curve. Keep up-to-date with the latest trends in SaaS financial forecasting and planning.Remember, your financial model is a powerful tool, but its effectiveness depends on the data you feed it and the insights you extract from it. By customizing and applying these tips, you can improve the value of your financial planning and forecasting and ultimately create a more sustainable business.

Read More >
Blogs

Securing Your Web Applications: Understanding and Preventing Broken Access Control

Securing Your Web Applications: Understanding and Preventing Broken Access Control

Introduction Broken Access Control (BAC) might sound like a minor issue, something easily spotted, but it’s actually one of the most frequently overlooked security flaws. While many focus on threats like Remote Code Execution (RCE) or Cross-site Scripting (XSS), BAC silently allows unauthorized users to perform actions they shouldn’t, often without any complex attack. A simple forgotten backend check can lead to sensitive data exposure or elevated permissions, just by slightly modifying the target web address. In this post, we’ll walk through how you can test for Broken Access Control using Open Worldwide Application Security Project (OWASP) Juice Shop—an intentionally vulnerable web application that makes it easy (and safe) to demonstrate these issues in practice. Understanding Broken Access Control Access control directs who can do what in a system. When it’s broken, users can act outside their intended permissions. Users might be able to read other users’ data, modify other roles, or access administrative functionality without authorization. OWASP defines this category broadly and it includes: Vertical privilege escalation: Accessing higher privilege functions (e.g., a user accessing admin functions). Horizontal privilege escalation: Accessing same role resources (e.g., viewing another user’s order). IDOR (Insecure Direct Object Reference): Accessing data by manipulating object references like user IDs or filenames. Forced browsing: Accessing hidden resources or unlinked pages directly. While it might be hard to understand these concepts at first, Juice Shop does a great job showcasing these problems in a safe, intentionally vulnerable playground. Testing for Broken Access Control For this simulation, you will need to install Juice Shop in your local environment and use Burp Suite to capture traffic while interacting with it.Gaining Privileged Access Juice Shop is a deliberately vulnerable web application that exhibits the classic Forced Browsing and Vertical Privilege Escalation vulnerability. Imagine if someone could access admin functions by just visiting a URL; that would be a security nightmare. Fortunately, we can demonstrate this in Juice Shop without the risk. You can test this by attempting to access hidden resources or unlinked pages directly using keywords such as “admin,” “root,” or other common path names in the URL. In our case, the Administration page can be accessed by visiting the “/#/administration” path. This page was not linked anywhere in the standard UI, yet entering the URL directly allowed full access to the user listing and the ability to remove customer feedback.Note that this vulnerability is accessible if you are already logged in or tagged as an admin role user inside OWASP Juice Shop. However, given that this is hidden in the user interface even if you log in as an admin user, we can infer that it was not meant to be exposed to users (including admin users). In some real-world scenarios, some web applications allow access to the affected endpoint to all users as long as they enter the correct address. But you’re probably curious how we can access this page using a regular, low-privileged accountFirst, inspect how the authentication works. Upon logging in, a token will be sent to your browser and subsequently attached to every HTTP request made to Juice Shop.At this point, you will have to study JWT, but let’s assume that you already know it. What do you think would happen if we change the JWT role parameter or claim to something else, like “admin”?You guessed it right. Modifying the JWT and changing it to “admin” allowed us to access the “/#/administration” page while logged in as a regular user. All you need to do is use Burp Suite’s JWT Editor extension, modify the role parameter or JWT claim to “admin,” go to your browser’s local storage, and replace the token key with the modified JWT, and Voila! You now have access to the Administration page even as a regular user.Viewing and Tampering Another User’s Basket This is an example of Insecure Direct Object Reference (IDOR) and Horizontal Privilege Escalation. Imagine if you have an e-commerce site and anyone can add or delete items in another user’s shopping cart. That would leave your customers confused. To test this vulnerability, log in as a regular user and inspect HTTP requests and responses related to user basket actions. In Burp Suite, notice that visiting your own basket generates a “GET /rest/basket/6” request to Juice Shop. Immediately, you can see from that request that our basket has an ID of “6.” Out of curiosity, if we change the basket ID to another number, will we be able to access other users’ baskets? It turns out we can. There are a couple of ways to test this, but by going to the browser’s Developer Tools > Storage > Session Storage, we can see a “bid” parameter. Modifying it to another number, in our case “3,” and refreshing the page would let us access basket #3—with no ownership check, just the data. This is an example of a horizontal IDOR vulnerability, where users at the same privilege level can access each other’s data by simply modifying object references.Alternatively, the details for basket #3 can also be accessed by repeating the original HTTP request in Burp Suite and modifying the ID to “3”.We were able to see the details of the other user’s basket, but how do we tamper with it? Let’s go back to Burp Suite and study the HTTP request and response flow. Notice that, besides viewing your own basket, adding items to our basket requires a “BasketId” parameter. This is the key to the attack. What if we modify the “BasketId” before sending the request? Will we be able to modify another user’s basket successfully? The short answer is yes, but it is not as easy as it sounds. But before we do the attack, we have the following in basket #3. Remember, our basket is basket #6.Now, let’s modify the “add to basket” request and change the “BasketId” to a different number. However, you will notice that trying to change it won’t modify the basket content of our target.So, what should we do? There are many things you can try, but to cut a long story short, you might discover that adding a second “BasketId” would push the request and modify our target’s basket as well.This tells us that if the backend interprets the requests, and if it finds another “basketID,” it will apply the same action to it. Do you see where I’m going with this? Perhaps adding more “basketID” values would enable a multi-basket attack, but I will leave that for you to try. This means that ignoring access control measures can lead to numerous issues in your web application, potentially affecting multiple accounts by disclosing sensitive information or, as in our case, the contents of a user’s basket. Forged user reviews In Juice Shop, as with almost every e-commerce site, users are allowed to write and submit reviews. This generally benefits both the store owner and enhances the overall user experience. But what if someone could forge a user review? What if a customer review was written and attributed to someone else, perhaps a high-profile user of the site? That would greatly affect the product’s performance, right? This is what we wanted to achieve here: post a user review and attribute it to a different user. Now, you’ll notice that whenever you write and submit a product review, this PUT request is sent.Remember our previous attack that affected another user’s basket? How about the attack where we found the admin email address (see Gaining Privileged Access)? Let’s test that. What would happen if we modify the author before sending it to the endpoint? Would that change the author itself? Let’s see.And what do you know, we were able to post a review using a different user! And we can confirm that by browsing the exact product in the web application.So, the lesson here? Yes, broken access control also helps attackers forge account actions. Directory enumeration and restricted file download One common pitfall of improperly implemented access control is that restricted directories and their included files become accessible for download. This vulnerability is often found in applications rushed to production or those that don’t undergo regular security testing. While this may be harder to find in the real world today, this vulnerability still exists in some web applications. But fret not, Juice Shop exhibits this weakness. If you’ve explored Juice Shop before, you might have stumbled upon various directories, including the `/ftp/` directory. You’ll notice that accessing this directory reveals a number of files without requiring any additional authentication. You can even access some of the files enumerated.Clearly, some of these files are not intended to be accessed, which in itself indicates an access control violation. If you further explore the directory, you’ll discover that attempting to access files with extensions other than “.md” or “.pdf” results in a restriction notification. As curious individuals, we’ll want to bypass this. Fortunately, Juice Shop is vulnerable to null-byte injection.Null-byte injection is essentially an implementation-related vulnerability stemming from a weakness in the framework, underlying library, logic, or a combination of all these three. To perform a null-byte injection, we need to append a null-byte (`%00`) to the filename, hoping that the application won’t sanitize our request.Initially, adding `%00` to the end of the URL might not yield results, perhaps because the server expects a valid file extension. To address this, let’s append a `.pdf` extension.Still not working, right? Perhaps something is blocking our request. Let’s see if encoding will help us get through. Let us encode % and see what happens.Well, what do you know, it works! Now we can access the restricted file and see its content. Clearly this is a violation of access controls. How to Prevent Broken Access Control? If you’re building or maintaining web applications, Broken Access Control (BAC) is one of the most important risks to address. Here’s what you can do to avoid the issues above: Enforce Access Controls on the Server Side Don’t rely on client-side code or hidden links. Every sensitive operation should include server-side checks against the user’s authenticated identity and role. Use Context-Aware Authorization and Centralize Access Control Logic Implement logic that not only checks the user’s role but also whether the user owns the resource in the specific transaction context. For example, confirm “user.id == order.ownerId” before returning order data. Centralize your authorization logic into a single reusable library or service. This ensures that robust authorization rules are applied consistently. This also simplifies maintenance.Adopt a “Deny by Default” and Least Privilege Principle Don’t assign admin rights unless explicitly needed. Make roles granular and restrictive by default. Implement Indirect and Unpredictable Resource Identifiers Use randomly generated identifiers like UUIDs/GUIDs. Implement an indirect reference map that translates a public identifier to a real database ID only after the authorization check has passed. Apply Rate Limiting and Throttling Apply rate limiting to endpoints, especially to sensitive ones such as authentication and data access, to slow down attackers trying to bruteforce identifiers Block IPs or users that exhibit anomalous behavior or exceed reasonable request thresholds Implement a Secure Development Lifecycle (SDLC) Include security unit tests and access control checks as part of your CI/CD pipeline. Use test accounts with varying roles to test for both vertical and horizontal privilege escalation. Monitor and Log Access Violations Set up alerts for unusual access patterns or repeated unauthorized attempts. Log every access control failure, including the user, IP address, and specific resource they are trying to access. Perform regular security assessments Perform regular Web Application Penetration Tests (VAPT) against your web applications. Engage qualified professionals to perform penetration testing at least annually or after any significant changes to the environment. Final Thoughts Broken Access Control topped the OWASP Top 10 list for a reason: it’s one of the most common and dangerous issues that plague web applications. While OWASP Juice Shop is intentionally vulnerable, the lessons it teaches are very real. If you are a developer, product owner, or cybersecurity professional, the insights from Juice Shop offer a humbling reminder of why access controls must be built defensively and verified thoroughly. Looking for support to assess your web applications? If your goal is to get a real-world, adversarial assessment of your security posture, including your access controls, Scrubbed can help you perform Web Application Penetration Testing. We can test Broken Access Controls and other vulnerabilities to help you secure your applications. Not your cup of tea? We also offer other information security related services such as IT audit, Security Awareness Training, and SOC assessment support. Get started in securing your organization. Contact us at https://content.scrubbed.net/contact-us/ (Risk Advisory).

Read More >

Contact Information

SF Bay Area Headquarters
111 Anza Boulevard, Suite 320, Burlingame, CA 94010, United States

Phone: (800)837-5160
Email: [email protected]

"Scrubbed" is the brand name under which Scrubbed Advisory, LLC and Scrubbed Assurance LLP provide professional services. Scrubbed Advisory, LLC and Scrubbed Assurance LLP practice in an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations, and professional standards. Scrubbed Assurance LLP is a licensed independent CPA firm that provides attest services to its clients, and Scrubbed Advisory, LLC provides tax, finance, and support services to its clients. Scrubbed Advisory, LLC is not a licensed CPA firm.

Copyright © Scrubbed. All rights reserved.