The recently published “OWASP API security top 10” report analyzes the anti-patterns that lead to vulnerabilities and security risks in APIs. In this 10 part series, we introduce these API anti-patterns. Every API professional should know about these anti-patterns.

If access control policies become too complex, for example by introducing many hierarchies, groups, and roles flaws in the authorization are more likely. Especially when there is no clear separation between administrative and regular functions. Attackers may exploit these issues to escalate their privileges, to gain access to the resources of other users, or to administrative functions.

The 10 most critical API security risks – Part 5: Broken Function-Level Authorization

Also published on Medium.