broken-object-property-level-authorization 1 Mass Assignment: A Silent but Devastating API Vulnerability Apr 20, 2026