Authorization and tenant isolation
Object-level access, role checks, cross-tenant boundaries, and admin-only paths.
- IDOR and broken object-level authorization
- Privilege escalation and missing ownership checks
- Cross-tenant and environment-boundary abuse