Glossary
Broken Access Control
A vulnerability class in which an application fails to properly enforce restrictions on what authenticated users are allowed to do, letting them view or modify data or functionality outside their permissions. It has topped the OWASP Top 10 list of web application security risks in recent years.