Insecure direct object reference is a type of access control vulnerability in digital security.
This can occur when a web application or application programming interface uses an identifier for direct access to an object in an internal database but does not check for access control or authentication. From Wikipedia