Broken object-level authorisation still wins in 2026
Framework defaults solved most injection classes. Authorisation is still handwritten, per-endpoint, and it is where our teams find the highest-impact issues.
Marta Kovacs · Application Security Lead