4
Insecure Design
High
Flaws in design and architecture that cannot be fixed by proper implementation. These issues require architectural changes.
Example 1

Architecture that doesn't implement layered authentication

Example 2

Design that allows direct access to sensitive resources

Example 3

Lack of validation in system design