Context-Inappropriate Capability
High
- Confidence
- 98% confidence
- Finding
- The example assigns a fixed admin role into session data immediately after login, which can mislead integrators into treating authentication as authorization. This creates a dangerous pattern where any authenticated user may effectively receive administrator privileges if downstream code trusts that session value.
