Executive Summary
Facts Only
* Broken access control ranks first in the OWASP Top 10:2025, with 100% of tested applications showing some form of it.
* Broken access control includes BOLA (broken object-level authorization) and IDOR (insecure direct object reference).
* BOLA is the failure to verify that a requester is entitled to a specific requested object.
* IDOR is exposing internal identifiers, allowing substitution to return data belonging to another account.
* The AI agent's generated code often follows correct procedural steps but misses necessary application-specific authorization checks.
* Authorization requirements are often unstated in prompts, leading agents to generate functional but insecure endpoints.
* Object-level authorization is resistant to pattern-based scanning because it depends on contextual knowledge (e.g., ownership rules).
* Static analysis handles pattern-based vulnerabilities well, but object-level authorization requires understanding the application's internal data model and access rules.
* Finding flaws that lack patterns requires reasoning over an assembled application context graph.
Full Take
From the original · Snyk Blog
October 1, 2026 0 mins readAI coding agents produce authorization logic that compiles, passes review, and enforces the wrong policy. Broken access control ranks first in the OWASP Top 10:2025, where 100% of applications tested showed some form of it, across 1,839,701 recorded occurrences, the highest count of any category on the list.Read the full story at snyk.io
Sentinel — Human
This analysis synthesizes known security concepts with a novel argument about the inadequacy of pattern-based AI code scanning for authorization flaws, relying on structured reasoning rather than simple aggregation.
