TL;DR: Broken access control remains OWASP's top application security risk in the 2025 Top 10, with OWASP citing an average 3.73% of tested applications containing one or more CWEs in the category, according to Cerbos. Ad-hoc role checks and code-embedded authorization no longer scale across microservices, APIs, and machine identities.
Editorial analysis by NHI Mgmt Group, based on content published by Cerbos: “Broken access control still tops the list: OWASP top 10 2025”.
Key questions
Q: How should security teams prevent broken access control in modern applications?
A: Security teams should move authorization out of scattered code and into a centrally governed policy model.
Q: Why do microservices and APIs make broken access control harder to control?
A: Microservices and APIs multiply the number of places where authorization can fail.
Q: What are the signs that authorization logic is failing?
A: Common signs include repeated role-check branches, inconsistent decisions between services, manual exceptions, and difficulty explaining why a user could act on a specific object.
Practitioner guidance
- Centralise authorization policy Move access rules out of scattered application branches and into a single governed policy layer that can be reviewed, versioned, and tested across services.
- Map object-level access paths Inventory where users can read, update, delete, or manipulate specific objects and look for force-browse, identifier tampering, and ownership bypass opportunities.
- Define contextual policy attributes Capture ownership, tenant, region, 2FA status, and approval thresholds as policy inputs so decisions can reflect the real business context of each request.
Bottom line: Broken access control persists because authorization logic is still too often embedded in application code rather than governed centrally.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Broken access control is a governance failure, not just a coding flaw. The persistence of this issue shows that authorization logic still lives too close to application implementation in many programmes. Once access rules are scattered across services and teams, consistency breaks down and exceptions multiply, so the control itself becomes hard to trust. The practical conclusion is that authorization needs central ownership and lifecycle governance, not just developer awareness.
A question worth separating out:
Q: How should teams govern authorization in complex application estates?
A: They should use centrally managed policy with versioning, decision logging, and consistent enforcement across all entry points. That approach makes access decisions auditable and reduces the chance that one team or service drifts away from the intended control model.
👉 Read our full editorial: Broken access control still exposes modern application authorization