The CVSS 8.1 on this IDOR in foreUP's API is technically accurate but substantively misleading — not because the severity is overstated, but because it obscures the systemic pattern that produced it. This isn't a one-off coding error. It's what happens when development teams treat authentication as a stand-in for authorization, reasoning implicitly that