Failures in enforcing what authenticated users are allowed to do — the most common web application risk. Includes missing authorization, privilege escalation, IDOR, and CORS misconfiguration.