IDOR
BackendReading someone else’s data by changing an id.
Insecure direct object reference: checking that a user is logged in but not that the requested record belongs to them. Trivially exploitable by editing a URL, and extremely common in generated code.
See also Authorization, Authentication