A01:2021 Broken Access Control
The #1 risk in OWASP 2021, found in 94% of applications tested. This occurs when users can act outside their intended permissions: accessing other users' data by changing a URL parameter (IDOR), elevating privileges, or bypassing access controls by modifying API requests. In 2023, a broken access control in a major airline's API exposed 12 million passengers' personal data. Defense: enforce access checks server-side, deny by default, and implement proper RBAC.