Broken Object Level Authorization remains the top API flaw in 2026. Meta's bug bounty program disclosed multiple IDOR vulnerabilities where authentication existed but server-side authorization failed at object level. Business logic flaws routinely evade automated scanners.