Broken Access Control
Access control failures, including object-level authorization gaps and SSRF, allow actions outside intended permissions.
The current OWASP web application security taxonomy, preserved as a distinct edition.
Access control failures, including object-level authorization gaps and SSRF, allow actions outside intended permissions.
Insecure defaults, unnecessary features, inconsistent hardening, and configuration drift expose systems.
Compromise or weakness across dependencies, build systems, distribution, and update channels.
Weak, missing, or incorrectly applied cryptography exposes sensitive data and trust boundaries.
Untrusted data is interpreted as code, queries, commands, expressions, or browser content.
Missing or ineffective security controls originate in architecture, threat modeling, and business rules.
Identity proofing, credential, session, and account-recovery weaknesses enable impersonation.
Software, updates, serialized data, and other artifacts cross trust boundaries without integrity verification.
Insufficient logging, monitoring, and alerting delays detection and response.
Fail-open behavior, improper error handling, and unexpected states undermine security controls.
Vulns.co preserves older editions at stable URLs and does not silently rewrite historical mappings.
Open the official OWASP edition ↗