Security writing tends to focus on sophisticated attacks. Real assessments rarely find them, because the sophisticated attack is unnecessary when a simpler route is open. The following issues account for the majority of what we report, in rough order of frequency.
Broken object level authorisation
This is the most common serious finding by a wide margin. An endpoint checks that you are logged in but not that the record you asked for belongs to you. Change the id in the URL from 4471 to 4472 and you are reading another customer's invoice.
It happens because the authentication check is visible and the authorisation check is not. The fix is to scope every query by the caller's identity at the data access layer rather than trusting a check further up the stack.
Class-level attributes overriding action-level intent
A controller marked as anonymous with individual actions marked as requiring authorisation. The class-level attribute wins, and endpoints intended to be protected are open. This is a framework behaviour rather than a typo, which is why it survives code review so reliably.
Secrets in the repository
Connection strings, API keys and signing keys committed to source control. Usually in a configuration file, sometimes in a test fixture, occasionally in a comment. Removing the file does not help once it is in history. Rotate the secret, then move it to environment configuration.
Mass assignment
An update endpoint binds the request body straight onto the entity. The form shows name and email; the request also accepts isAdmin. Use explicit request models with only the fields a caller is permitted to change.
Missing rate limits on authentication
Login, password reset and OTP verification endpoints with no throttling. Six-digit codes have a million combinations, which is a meaningful barrier at ten attempts and no barrier at all at ten thousand per minute.
Verbose errors in production
Stack traces, SQL fragments and file paths returned to the client. Each one is a small gift to anyone probing the system. Log the detail, return a correlation id.
Uploads validated by extension only
A file named invoice.pdf that is a script. Check the magic bytes, store outside the web root, and never serve uploads from a path that can execute.
The pattern
None of these require unusual skill to find or to fix. They persist because they are invisible in normal use: the application works correctly for a well-behaved user, and nothing in ordinary testing exercises the misbehaving one. That is precisely what an assessment is for.