What qualifies as Broken Access Control ?
Broken Access Control
An unauthenticated user being able to access a page/document reserved for users
An authenticated regular user being able to access a page/document reserved for admins
An authenticated regular user being able to access a page/document reserved for users, but access another user's informations
A crafted link that tricks someone to take actions on it's own account/datas